

OGID : 



3560816 



V 





ARMY SECURITY AGENCY 



Washington 



i 

i 



* } 



Declassified and approved for 
-elease by MS A on 06-01-2009 
Dursuantto E.O. 12958, as 
amended. Declass 58017 




EUROPEAN AXIS SIGNAL INTELLIGENCE Ili 

i * * f 

• m 

m 

AS REPEALED BY "TIC0M' ! INVESTIGATIONS 



EXEMPT . 1 
Classified/Extended by DIRNSA/CHCSS 
Reason: NSA Declassification Guidelines 

Date V 



- is 




I- 



L - 




\ 

\ 



X 



\ 





AND BY OTHER PRISONER OF WAR INTERROGATIONS 



AND CAPTURED MATERIAL « PRINCIPALLY 



VOLUME 2 --NOTES ON GERMAN HIGH LEVEL 



CRYPTOGRAPHY ANBURY? T ANALYSIS 



i 

Prepared under the direction 



CHIEF „ ARMY SECURITY AGENCY 



1 May 19^6 




D: 3560816' 





NOTES OK GERMAN HIGH LEVEL CRYPTOGRAPHY AND CRYPT ANALYSIS 



Chapter I 



The Paradox of German High-Level Cryptography 



Chapter II 



The Enigma Cipher Machine 



Chapter III Teleprinter Cryptographic Apparatus 



Chapter IV 



Cipher Device the Cipher Box, the Cipher 



Disk 3 and the 



"Kumher Printer." 



Chapter V 



German Ciphony 



Chapter VI 



German n I.B.M." and Rapid" Analytic Machinery 



Chapter VII 



German Cryptanalytic Methods 



S 



J 




DOCID: 3560816 




Volume 2 



Chapter- I The Paradox of Ger 



Ml 



High 



Paragraph 

German high-level cryptographic systems were 

insecure, although brilliantly conceived 1 

German military cryptographers had secure cipher 

devices under development a 2 

German security studies revealed only theoretical 

weaknesses of their cryptography... jj 

Interrogation of Anglo-American prisoners failed to 

disclose German cryptographic weaknesses..... 4 




1 . German high-level cryptographic systems were insecure , 
although brill i antly cone eivea -- German high-level crypto- 
graphy was brilliantly conceived (as will be shown in this 
volume) but more brilliantly conceived cryptanalytic pro- 
cedures and large expenditures ijn manpower and rachinery by 
the United states and British Qovernments, in one of the 
most dramatic chapters of World War II, accomplished daily 
solutions of . German high-level systems that cost Germany 
heavily, if they did not, as some believe, bring about actual 
defeat. For instance: 

a. The German Air Force lost the Battle of England in 
l^^O, partly because it entrusted bomber- target information 
to the insecure Air Force Enigma. Unknown to and even un- 
suspected by the Germans, their operations from this date 

on were constantly embarrassed by the cryptographic insecurity 
of this machine. 

b. The German Army suffered terrific casual uy» and 
losses, of materiel in Africa and on the continent because 
of^blind, faith in two of its hi*h level 

achlnes: the Army Enigma, 
ent ' 9 SZ-42. tf Both were insecure. 



high 
and th 




ilitary cryptographic 
teleprinter cipher attach* 




1 



The great debt England owes it'.cryptanalysts is to be re- 
corded in a history of the Government Code and Cypher School, 
London, to be available in the fall of 1<H6. The statement 
here is based on verbal information from intelligence officers 



and cryptanalysts 
tion. 



2 



of the School, and awaits proper documenta- 
This history will also include data regarding the 
German Army and Navy Enigmas . 

A written report by Brigadier E. T. Williams, chief intelli- 
gence officer to Field Marshall Montgomery, 5 October 19^5, 
to be included in the Government Code and Cypher School his- 
tory, gives specific examples bearing out this statement. 



DOCID: 3560816 





Co The German Navy lost a staggering number of submarine 
for a similar reason: insecurity of the Enigma, Navy version . 

d. The German Foreign Office employed three main systems, 
all insecure * Two of them (the Deutsches Satzbuch unenclphered, 
and the Deutsches Satzbuch enciphered by "Ploradora, 11 ) w 
read during the war; the third system (a "one time pad/ 1 
Security Agency trigraph "GEE") was read only in the last 
six months of war* but gave information of much military value 

the 




Army 



against 

. 2. 



apanese 



«1£ 



ill tar 




apher ^ had secure cipher 



devices under development -- It is a paradox that German high* 
level cryptography was a "practical" failure and at the aame 
time German 



ill 1 tar y cryptographers had so 

of development, 
ite; 



tany secure devices 



in various stages 

a. One simple item alone, a "variable-notch" rotor, would 
probably have prevented Anglo-American attempts at reading the 
Enigma after 19^2, if it had been produced in quantity and 

installed. This rotor was called "Lueckenf uellerwalze. 



3 




The real truth behind these losses has been and still Is at 

this writing (May 19^6) so carefully concealed that the 

following^ statement by Admiral Doenitz In the Nuremberg trial 
is of considerable interests "The Battle of tu& Atlantic was 
nearly won prior to July 19^2 
reasonable limits. 



when German losses were within 



But they jumped 300 per cent when Allied 
aircraft, aided by radar, which came like an epileptic stroke, 
were used in the fight/ 1 He reported 640 to 6?0 submarines and 

30,000 men lost as a result of British and American action. 

(See IP 259), A capfoured, unsigned, naval report dated 19^4, 
evidently sent to the Navy High Command regarding cipher security, 
stated: "... ♦ the high degree of efficiency of the enemy 9 s 
aircraft Radar, so often surprising, has received remarkable 
and decisive assistance from directions based on the results 

the direction finding service." (See IF 142)„ It was never 
realized that cryptanalysis, rather than radar and direction 
finding, disclosed the positions and intentions of the German 

submarines . 



of 



7 



4 



M 11} I 104 pp 2,5 



2 




— 



- 



DOCID: 3560816 





This 




b. An irregular-dri^e Enigma that would have defied all 
presently known methods of solution, was being developed 0 
was called "Cipher Device 39" { "Sehluesseigeraet 39, 11 abbrevi- 



ated "SG-39 

c. An 



improved "cipher 
stalled on several circuits, 

reading of teleprinter 
reading 




teleprinter" had been built, in~ 
and used, which prevented easy 

s in depth j and even if this 
in depth was accomplished, the machine remained secure 
against known methods of attack as far as all other messages 
enciphered by it were concerned . This was called "cipher 
teleprinter T-52e" ('Schlugsself ernschreibmas chine T~52e," 

abbreviated "SPM T-52& ir ; 

d. Apparatus was being developed for "cryptizing" a 
radio teleprinter circuit — that is, for applying a basic crypto 
graphic process to the circuit itself even before any intelli- 
gence is superimposed on the emissions. This was called 
"cipher attachment 42c" ( "Schluesselzusatz 42c," abbreviated 
"SZ-42C 1 *) , which was to be used with a continuously operating, 
crystal-controlled, synchronized teleprinter.' 

e. A mechanical, portable, keyboard-operated cipher ma- 
chine, employing an interacting wheel -motion principle applied 
to Hagelin-type wheels, had been developed and built and parti- 
ally distributed, which would have been completely secure 
against reconstruction even if messages were read in depth. 
This was caliM "Cipher Device 4l" ( "ScUluesselgeraet 41," 
abbreviated "SG-41")? It was cryptographieally superior to 
its mu&h smaller U.S. Army equivalent device, Converter M-209. 

f. Other devices were also in varying stages of develop- 
these included the "Cipher Box" ( "Schluesselkasten") , and 

Cipher Disk" ( "Schluesselscheibe") , which were two minia- 
ture enciphering devices intended for use by secret agents 



ent 
the 



2 
11 



and by the Army. 



9 



5l 
6 



55 



I 20, I 31. In this document the term "cipher teleprinter" 
will tic employed consistently to designate a teleprinter in 
which the cryptographic mechanism is an integral part of and 

is contained thin the machine itself; the term "teleprinter 
cipher attachment, w to designate an auxiliary cryptographic 
echanism associated with the teleprinter but not an integral 

part thereof. 



7 1 57 E 14 



8 
9 



I 72 

I 20 I 96 



2 




DOCID: 3560816 





b 



The foregoing devices have been studied and are being 
studied by cryptographers and cryptanalysts at the Army 
Security Agency, and the general opinion is that the Germans 
were making rapid strides toward greatly improving their 
communications security. 

The very least that can be said is that they had something 
different , Their teleprinter devices employed mechanical cipher 
wheels, as opposed to the U,S 4 Army and U.S. Siavy use of elec- 
trically-wired cipher wheels ("rotors"); furthermore, the mechani 
cal ¥heel arrangements, in their new devices, were highly deve- 
loped and secure. They also employed interacting wheel motions 
(wheels mutually controlling one another) for several of their 
cipher- teleprinters, as well as for their SG-^l (Hagelin-type 

achine). Mechanical wheels and interacting wheel motions for 

teleprinter enciphering devices have long been considered by 

United States cryptographers; our developmant along other lines 
has been from choice. Hone of our present devices uses inter- 
acting motion, and the excellent developments of the Germans 
not only furnish us greater insight into such possibilities, 
but also increase* greatly our store of knowledge. 

■ j 

3. German security ;_ studies revealed only theoretical 

wea kne sses , off their c ryptography— Ger 
sraphers failed to re 




raphy -- German military crypto- 

their existing Enigmas and 
graphic apparatus were insecure 
unable 



their security 



This was 
to put 



forth the costly practical effort required to solve them. Their 
security studies were theoretical only, ^ since actual traffic 
was never obtained for such studies. 11 



They were completely 
practical knowledge of how successfully a careful and 
ned attempt at traffic analysis can provide daily "cri 
er data for cryptanalytic attacks and they had not ad- 
suff iciently in applied 



, they 
d cryptanalysis to realize that 
determined engineering staffs can produce ite 
(rater French, later English, later American) "bombe," the U.S. 
ISavy "duenna," the Army Security Agency "autoscritcher, n or the 
British "colossus." The flashes of intuition and inspiration 
that come from doing, as well as theorizing, 



10 



4L 



I 45 pp 4,5 
I 21 



4 




DOCID: 3560816 




A report on naval ciphers dated 10 July 1944, apparently 
written toy the Signal Security Agency of the Navy High Com- 

and (OKM/4 SKL/lI), stated that solution of the naval Enigma 
was conceivable, based on "the assumption of extraordinary 
mechanical outlay on the part of the enemy for cryptographic 
activities,,., though we $KHl/k SKL/ll/ can conceive of a 
achine which would be suitable for this kind of work, we 
have none available or unde? consideration, since the whole 
question does not yet appear to justify undertaking such a 
difficult special constructional problem." 12 The British did 
undertake this problem, and were rewarded with astounding 
success, 

4. Interrogation of Anglo-American prisoners failed to 
disclose German cryptographic weaknesses-- Furthermore / TICOM 




reveals that Germany never became aware of the Anglo-American 
solution of German high grade systems. Not even a hint of this 
fact came to them through their agents, their interrogations 
of Anglo-American prisoners of war, or their cryptanalysis . 

It may be said that Germany lost the cryptologic war even 
before 1939* in PC and. The Poles invented the "bombe," 
a device which later, in improved form In England and In 
America, provided daily solutions of the German plugboard 
Snigma. The "bombe" secret was almost revealed when three 
deciphered German messages were found by the Germans In Po- 
land In 1939. The Germans became alarmed and conducted many 
interrogations; 13 the case was re -opened In 1942 and 1943; 
but at no time did the Germans learn the real secret of the 
Poles 1 success. The Germans became convinced that probably 
the iSnlgma indicator system had been at fault (as it partly 
had been) and since it had already been changed In 194G, 
they were no longer concerned with the suspected solutions. 

Also, there were Intelligence officers who feared that 
Enigma traffic was insecure, but their fears were based only 
tffihlnference and not on direct proof* Thus, when the Mavy 
High Command became alarmed at mounting submarine losses, 
the Increasing effectiveness of Anglo-American airplane radar 

was blamed, and the Snigma was exonerated. 1* 



12 IP 142 

15 I 127 

14. 



s 



volume 



5 




» 



DOCID: 3560816 





An intelligence officer attached to the Air Force High Com- 
mand at the time of the landings in North Africa expressed 
his suspicions, to the Chief Signal Officer of the Air Force, 
a General Martini, and caused him to reduce "his earlier be- 
lief in the 100$ security to 80^ security, but his evidence 

was insufficient to cause the Air Force to discontinue use 

of the Enigma. 

Germany was unable to cryptanalyze British and American . 
high-grade systems carrying cryptanalytic operational infor- 
mation and other ULTRA matters between England and America. 
As a result she had no hint from crypt analyst that her own 
high-grade systems were insecure „ 

It is absolutely clear that United States and British 
security regulations applicable to ULTRA were so good and 
so closely adhered to by all concerned that knowledge of our 
Enigma-solving and teleprinter-solving 

of 



from the Germans. An 
German cryptanalysts. 



interrogation 
Drs. Huettenhain 



operations was kept 
two of the 



leading 
and Fricke of the Sig- 
Command Armed Forces 




nal Intelligance Agency of the^Supre 
(OKW/Chi) revealed only that: 1& 

' "One Allied PW in North Africa had said the United 
, States and British operated with a very large joint 
•park 8 of I.B.M. machinery, but this interrogation was 
never followed up. Ho personalities whatever were 
known." 



15 

16 



IP 5 

I 84 p 6 



6 




\ 



DOCID: 3560816 




Volume 2 



Chapter II The Enigma Cipher Machine 

Paragraph 



Enigma cipher machine was the backbone of German 

high-level cryptography .«...<, ....... 5 

Commercial Enigma was known to be insecure. ........ 4 .... . 6 

"Counter" Enigma was known to be insecure „ ........ 7 

Plugboard Enigma was believed safe if used properly « 8 

Plugboard Enigma was known to be solvable with "cribs "... 9 
Theoretical weaknesses of plugboard Enigma were . 

understood. ................. ♦ 10 

"Variable-notcih 91 rotors ;,would probably have made 

plugboard Enigma securb r 11 

Cipher Device 39 would have been secure against 

present attack 12 

Enigma development is worthy of study 13 



\ 5* Enigma cipher machine was the backbone of German 
high-lev el cryptography — The Enigma cipher machine , in 
five different forms, was used by German commercial firms, 
^ by the Post Office, the Railways, and miscellaneous other 
German government departments; by the Supreme Command of 
the Armed Forces; by the High Command of the Army, and in 
Army communications down through division; by the High Com- 
mand of the Air Force, and in Air Force communications down 
through group and sometimes squadron; by the High Command 
of the Navy and in Naval communications down through sub- 
marine; by Military Intelligence (Abwehr), by the Reich 
Security Office (Reichssicherheitshauptamt, abbreviated 

" RSHA " ) ; and by Military Attaches. 

The five main forms in which it appeared were called 
, the commercial (or "K") Enigma; the "counter" (or "Zaehl- 
werk") Enigma, sometimes called the "Abwehr " Enigma or the 
"G" Enigma; the plugboard ("Stecker") Enigma; the plugboard 
with (pluggable) refiector-D ( "Stecker mit Umkehrwalze D") 
Enigma; and the Navy Enigma. The plugboard Enigma with 
"variable-notch" rotors ("Stecker mit Lueskenfuellerwalzen") 
was to have appeared soon. Another model, Cipher Device 39 
( "Schluesselgeraet 39") was under study. See Chart No. 2-1 
herewith. 



r 



DOCID: 3560816 



0) 




Enigma 
I'odel 



Commercial 



Counter 
("Zaehlwerk") 



Plugboard 
("Stecker") 



Navy 

Plugboard 



Plugboard 

with pluggable 

reflector 

( Umkehrwalze D) 



Plugboard with 
variable notch 
rotors ( Lue ckeh- 
fuellerwalzen) 



Used by 



Number of 
rotors 



Commercial firms 
Reichspost j 

Reichs bahn o K'is c o 
govt, depts* 



3 



ililitaxy attache* 
until 1943 j then 

Heich Security 
Office 



3 



Command 3 from 



Army* Air 



set of 5 



Navy standard 
machine 



Just beginning 
to be used by 

Air Force,, Pro- 
posed for Armed 
Forces and for 
Army 



Proposed for 
Armed Forces, 
Amy, Navy, Air 



3 from 
set of 

5 ? . 



3 from 
set of 8 
& 1 from 2 

3 fro; 
set of 5 



Cipher Device 
39 (Schluessel- 
geraet 39) 



Proposed for ■ 
Armed Forces, 
Am\y, Navy, Air 



4 variable 
notch 

rotors from 
set of ? 




Number of 
notches 
per rotor 



1 



Multiple 
but fixed 



1 



5 vdth 1 
3 with 2 
2 with 0 



1 



Multiple, 

CHANGEABLE 



fore non- 
predictable 




Type of 
reflector 



Type of 
end plate 



How machine 
would be solved 



Rotor, not 
pluggable 



Not 

pluggable 



4 or 5 letter crib 
and catalogue; or 
rapid analytic 
machinery « ( Bombs , 
duenna or scritcher 
not needed.) 



Rotor o Not 
pluggable 



Not 10 letter crib and 

pluggable catalogue; or rapid 

analytic machineiyo 
(Bornbe, duenna, or 
scritcher not needed d ) 



Fixed plate 
Not pluggable 



PLUGGABLE 



Bombe (duenna or 
scritcher not 
needed) e 



Fixed plate 
Not pluggable 



PLUGGABLE 



Bombe, duenna, or \ 
scritcher 



Fixed plate 
PLUGGABLE 



PLUGGABLE Duenna or scritcher 

VaKY DIFFICULT. 



Fixed plate 
PLUGGABLE 



PLUGGABLE 



and there- or not 



Bombe, duenna, or 

scritcher (if at 
all possible) 



pluggable 



Multiple, 
changeable; 
plus Hage« 
lin type 
drive 



Fixed plate 
PLUGGABLE 



PLUGGABLE 



Bombe, duenna, or 
scritcher (if at 
all possible) * 



PROGxiESSlVE CHANGES IN GEBKAN JSNIGtA 



Chart Noc 2-1 



DOCID: 3560816 




6. 



Commercial 



it 



aethods and which involved small prepared 



, anig ma was known to be insecure*-- It 

vras well known by the Germans that the commercial Enigma was 
not difficult to solve. They suggested hand methods 
"stripping off the fast-moving rotor/' vhich were almost 
identical with our 

catalogues . 2t) They suggested statistical methods using rapid 

analytic machinery. 21 They had also investigated the machine 

mathematically, from a "group theory" standpoint. 22 The com- 
mercial machine had been, until about 193$, sold on the com- 
mercial market by the German firm which owned the patents and 
developed themj but soon after the Na^i accession into power 
the machine was withdrawn from the market. The Germans furnished 



these 




ans 



achines to the Croat puppet government.^ The Ger 
themselves used it for their post office, their railroads, 
and other government agencies. Because of its insecurity, 

every message enciphered by it was supposed to be re-enciphered 

at a second setting, 2 ^ a procedure which if adopted would 
have made 



the 



essages quite seoure. 
procedure was gengpally carried ont, 
culties involved. 





It is doubtful if such 
because of the diffi- 




7. " Counter" Eni 
counter" Enigma I 



known 



The 



counter in its 



because it incorporated a letter 
tiachanism) was important because it introduced 

multiple-notch rotors. In general, the 

-ing rotors in machines 



In general, the more often encipher 
f the Enigma class step, the more 
difficult solution becomes, and 
about this desirable 



Lultiple-nbtteh rotors 



otion. Even so, tlx 
was known to be solvable by short cribs. 2 

sued with this 




counter 



being 

achine 



also 

sage, 
in 

drawn 





Regulations were 

achine to double -encipher each 

Only about 100 of the "counter" machines were made 
all; they were issued to German military attaches, 
in 19*5 * and issued to Military I 
ere also sold to the Dutch govern 




with- 
Abwehr ) 



2 _Pl 

21 



22 

25 
24 

25 
26 

27 



47 



I 45 

T 372 

I 92 



I 92 

I 92 

I 77 
I 77 



28 I 104 



9 




3560816 



8. 



i 

;board Enigma was believed safe if used properly — 



4h 



Plugboard Enigma was us 



y the Supreme 
by the Army, by the Air Force, and, 



ommana Armed Forces, 
with an additional rotor, 



by the Navy, as the ubiquitous and "secure" cipher device 



It 



and 



able to carry highest-level traffic "if used properly." 
was also supplied to the Hungarians, Rumanians, Finns, 
Italians. y Investigations by Dr. Pietsch, of the Signal 

Intelligence Agency of the Army High Command (OKE/G d HAk 

showed the safety margin to be 20,000 letters a day .3° Dr. 
Fricke believed that if the instructions on maximum lengij. of 



uassages were followed, 



"everything would be all right. 
Yet it was traffic in this Enigma, even when "used properly," 
which was regularly solved day-by-day by the tremendous Anglo 
American cryptanalytic effort. 




It is 

knew n 



9. 



board 



an 
at 



astonishing ra<jt that althou 



ta was known to be solvable with "cribs. 1 



German cryptographers 
least as early as 19^3 * that it was theoretically 
possible to solve the German Army plugboard Snigma whenever 
a proper crib was available, 52 they seemed little concerned 
about this possibility and failed to realize that a practical 
solution might be based upon it. This knowledge should have 



because 



ight be based upon it. This knowledge 
aroused their most vivid apprehensions but did not, 
of lack of imagination regarding the possibilities presented 
by the invention, development, and use of specially designed 
high-speed analytic machinery. 

In 1944, Lt. R. Hans -Joachim Frowein of the Signal 
Security Agency of the Havy High Command (0KMA SKL/II) sug- 
gested an International Business Machine (l.B.MU) method of ^ 
solving the plugboard Enigma, given a twenty-five letter crip.?' 

This suggestion was based on a hand method which employed 
sequential testing, or "scritching, " a method which was me- 
chanized by the Army Security Agency and incorporated in the 
"auto-seritcher ." After describing this, hand process, Lt. 
Frowein made the following suggestions:-^ 



29 



T 92 P 2 



30j 78 



31 



I 20 



3 2 D 58 



P 




33 
3* 



I 38 pp 3-^ 

I 38 p h 



10 



r 



DOCID: 3560816 





"In practice, Hollerith ^i.B.M./ 

"be used. 



achlnery would 



ft 



With a 3-wheel (Army) Enigma, only 



70,000 



cards are required. 



The enemy could have preluded 

the war and this 



the 70,000 cards at the beginning of tne war 
catalogue would have been valid throughout the life of 
the three^wheel Enigma. The first Hollerith card sort- 
ing process would take 200 machine -h our s Q the second 
only 8 machine -hours, and so on. 



Thus a total of approximately 22Q X/B.M. sorter -hours 
would have been sufficient to test the "crib" to see if it 
could break the plugboard machine. Another way of stating 
this, is that 10 sorters could test one crib in one day. 
This is not rapid, but it is within practical limits 0 And 
this suggestion is only the f ir&t theoretical answer, not 
the climax of a comprehensive, practical 

Perhaps the cryptographers of the Signal intelligence 

_e Command Armed Forces (OKW/CM) believ 
that it would be too difficult for an eraemy to obtain the 

cribs necessary for solution by Lt. Frowein°s methods. Pos 

sibly they were too busy designing 
they would put into effect "someday." Certainly there is no 
indication in the TICOM interrogations or documents that 
cryptographers of either the Ar 



to the 

Enigma , < 

stated:? 




The Wavy, with a four-rotor 

d take his results somewhat 



the results were shown 
ore nearly secure 
riously, Lt. Prowein 



"The official reaction to the findings of the 




■4" 



investigation was the immediate decision /by the Kav^7 
that only rotors with two turn-overs should be allowed 
to be used in the right-hand ^"fast'^7 position- This 
potion/ ^as introduced at the beginning of December, 

19**.'.. . The view of the German Army was that their 

our -rot or 




ava 



wa s theoretic 

gma was not cons 



eoret 



e A rmy were aston 
n ve s t iga 




vable 




on 



The action taken by the Havy, as indicated above, was 
so ineffective an answer to the problem raised by Lt. Prowein, 
that it almost might as well not have been taken. Neverthe- 
less, for his excellent work, Lt. Prowein was awarded the War 
Merit Cross. 



35 I ?8 P 5 



11 



Q 



DOCID: 3560816 






10. Theoretical weakn esses of 

underst oodr*- We may not conclude from 
pr ac t 1 eal~eff or t s 



board 




to make a worthwhile security study of 

the plugboard Enigma that the German military cryptographers 

were in any way mentally inferior to the British and Ameriaan 
cryptanalysts who succeeded against this Enigma. Despite 
that fact that the Germans discovered every weakness the 
Enigma had, their theoretical studies and conclusions ap- 
parently did not impress them. According to Dr. Buggisch 
of the Signal Intelligence Agency of the Army High Command ^ 
(OXH/G d HA), the weaknesses of the plugboard Enigma* were:- 56 



a. Rotor I (the "fast" rotor) moved uniformly,, 
b* Rotors II and III moved too seldom. 
c« The machine needed more than three rotors to 

inserted in it at once. That is, the period 26 

too short. 

d„ The machine needed mope than five rotors to be 
issued with it. That is, the number of rotor orders, the 

permutations of 5 rotors t&ken 3 at a time (- 60), was too 

e. The reflector was not pluggable,, and the "enemy" 
could set up the 60 x 26 2 x 25 alphabets of the machine 
in its unplugged form, possibly, proceeding to a solution 
from there. 



be 

x 25 was 



Dr. Buggisch was so rights Improvement in any one of 

the foregoing particulars could easily have pushed the plug- 
board Enigma beyond the reach of already- straining Anglo- 
American cryptanalytic fingers, and possibly altered the 
course of the war. If the multiple turn-over rotors of the 
"counter" machine had been inserted in the plugboard Enigma, 
if t?n rotors had been issued instead of five, if five rotors 
simultaneously could have been used in the machine instead 
of three, if the rotors already in it had been kept more 
active by suitable motions, or if a pluggable reflector 
had been universally adopted, regular, day-by-day solution 
would hardly have been possible. 





36 



I 57 



^Another effective security measure would have been to issue 
new rotors at regular intervals, or whenever compromise of 
those in use was suspected. This procedure wa3 evidently 
not considered favorably by the Germans, who had 30 many Enig- 
mas in the field and in use elsewhere, that the chance of 
capture was great, and the number of rotors to be replaced in 
case of compromise prohibitive. Wewly wired rotors were 
issued at the outset of the war, but these wirings were kept 
throughout the war without change, on the theory that the Enig 
a was secure regardless of rotor compromise. 

12 







DOCID: 3560816 





How close the Anglo-Americans came to losing 
solution of the German Ar: 
analysts pause. 

British and American cryptanalysts recall with 
how drastic an increase in difficulty resulted from 



Lction by the German Ai; 
Umkehrwalze D " called 



the 



Spring 



of 19^5 ♦ It made completely obsolete the "bombe" 
>ry which had been designed and installed at so great an 
expense for standard, plugboard -Enigma solution. It neces- 
sitated the development by the U.S. Havy of a new, more complex 
machine called the "duenna," and by the U.S. Army of a radi- 
cally new electrical solver called the 
of these had to make millions of 



"autoscritcher . " Each 
tests to establish simul- 



taneously the unknown 
reflector plugging. 



and the unknown 
Only a trickle of solutions would have 
resulted if the pluggable reflector had been adopted univers 
allyj and this trickle of solutions would not have contained 
enough intelligence to furnish the da 

subsequent solutions. Thus even the 
ally vanished. 

Credit must be given to the unknown German 

cryptographer, possibly a 



trickle would 



tember of the Security Group of the 
Signal Intelligence Service (OKL/Gen Nafue/lll 
who brought about the use o 

Air Force in the 



an 



Gruppe IV), 
throughout the Ger- 
spring of 19^5 • It is indeed lucky for 
the Allies that the cryptographers of the Signal Intelligence 

Agency of the Supreme Command Armed Forces (OKW/Chi) did not 

agree with his belief in the pressing need for additional 

security. Dr. Fricke said;58 "it was not considered important 

as the plugboard was the real safeguard." Dr. Huettenhaln 
said in effect:-^ "The G.A.F. had intr 



reflector, 

* 



>duced the plugg 
Army said it was too much trouble." 



" Variable-notch" rotors would 
lugboard Enigma secure — Daily solution 



>r obably have mad e 

oar 



gma would probably have been prevented if the Germans had 

introduced the variable-notch rotor ("k^eckenfuellerwalze") 

in 19^-3 as planned. 

This rotor was designed to "hold the security line" until 

the introduction of Cipher Device 39, a Hagelln-t^npe-drisre 
Enigma, designed in 1959 (as its name implies) and already past 
the blueprint stage. 



38 

39 



I 20 
I 31 



13 





a- 



DOCID: 3560816 




The effect of variable -no t:ch rotors in an Enigma would 
have been to make impossible the foretelling of exact suc- 
cessive rotor settings, when preparing to "bombe" a crib. 
Assumptions would have to be made as to the presence or absence 
of turn-overs of the "medium speed" and "slow speed" rotors, at 
each successive element of text. This would have multiplied the 
number of trials necessary to test cribs, and thereby reduced 
the number of solutions to the small, trickle which has already 
been characterized as not being* in all probability, self- 
sustaining* 

The following excerpts from minutes of conferences 
held by the Signal Intelligence Agency of the Supreme Command, 
Armed Forces (OKW/Ghi) on X>_ December 19^3 and 18 March 1944, 
are interesting sidelights ;40 




a. "Concerning improvement of the Enigma, Wa Pruef 7 
/Army Ordnance, Development and Testing Group, Signal Branch^ 
stated that the replacement of all rotors by variable -notch 
rotors required reconstruction and time for develop 
It was however possible to exchange one rotors the necessary 
variable -notch rotors could be delivered within a reasonable 
time." 

b. "In collaboration with Wa Pruef 7, In view of the 
Introduction of the variable-notch rotor . the keying pres- 
sure /required to encipher on the Enigrw was reduced by abo 
1000 gr. at the firm of Kei^soeth & RinSe." 



Mechanical drawings of the variable-notch rotor 
In the files of the Army Security Agency .41 Several 
rotors have been paptured and are available. 



are now 
such 



her Device 



wou*,d have been secure 



12 . _ 

r esent attack -- Cipher bevice 39 ^ ag to be the epitome 
gma perfection. It was to have everything — end-plate pluj 
board, pluggable reflector, 4 variable-notch rotors, 2 added 
Hagelin-type irregular drive wheels, and a simple Inter-acti] 
motion. It was to have a keyboard; and it was to print both 
plain and cipher texts, at a rate of 85 words per minute. 

A note in Dr. Huettenhain* s files dated 
stated:* 1 




40 
41 



D 59 p it 

M 11 



42 



ii 



p 



v 



D 59 P 26 




3560816 

i 



"The model built by the ple^f onbau u. Siormalzeit 
Company, Frankfurt a. Main is being demonstrated in 
operation. The machine essentially satisfies all the 
requirements laid down for it, Wa Pruef 7 /Avmj Ordnance, 

Development and Testing, Signal Branch/ settled what 
features of the machine require improvement. P.AoH. 
(?) in Frankfurt a. Main has been completely destroyed . 
The machine cannot therefore be expected to go into large 
scale production there for some considerable time. It 
is therefore intended to get an additional production 
center at once. The Wanderer Company, whigh already has 

wide experience of large scale production, is proposed 
for this additional production. Dr. Pess of Wanderer 1 s 
is awaited in flanken for detailed negotiations on the 
subject of this production. 

"According to Wa Pruef 7 ^Srmy Ordnance, Development 
and Testing Group, Signal Branch^ small scale production 
is approved. 

"OKW/Chi sees at the moment no possibility of a 
break- in, but exhaustive investigations are still in 
.* Progress . 

"On completion of plant at Wanderer it is planned 

to arrange a final conference there with the units re- 
quiring the machines and the special committee. The aim 
is to begin large scale production by the end of 19 W 

p ■ 

None of the test models of Cipher Device 39 has ever been 
received. at Army Security Agency. * Excellent descriptions 

■ 

test models of Cipher Device 39 were packed in boxes at 
Telef onbau u« Eormalzeit, Frankfurt, and the boxes "picked 

up by an Army Corporal on March 22, 19^5 > for movement to a 
military depot at Tauberbischef sheim. " See 1-53 P 3. These 
were never found. A third, incomplete, machine however was 
captured and is now at London Signal Intelligence Centre. 
Captured German Army plugboard Enigmas, commercial Enigmas, 
counter Enigmas, variable -notch rotors, and pluggable reflector 
wheels -i ^are available at the Army Security Agency museum, 

however. 

i ■ 

* ■ 



4 

r 

15 



1 r 



f 



DOCID: 3560816 




exist, however, 1 *^ 

repines en ted by the 



The main elements of this device may be 
following skeleton schematic diagrams 




Vari- 
I able 

f notch 
rotor 



5 



Reflector 
plate, pi uggabl e 







I 



Vari- 
able 
notch 
rotor 




8 Hagelin 
type 
drive 

wheel 



Vari- 
able 

notch 
rotor 




■ 

I 

Hagelin 

type 

drive 

wheel 



4 




(Vari- 
able 

notch 
rotor 



T 
i 




Hagel in| 
type » 
drive 

wheel 



End plate, 
pluggable 



44 



39 was originally 



Scanned 



1-53* 1-57. It is interesting to note that Cipher Device 

to have been issued in 1939* 
as its name implies. A TICOM report on an interrogation of 
Dr. Otto Buggisch of the Signal Intelligence Agency of the 
Supreme Command Armed Fcrces (oKVf/Chi) stated: "Geraete 39 
and 4l were both in development for years and still had not 

come out at the end. B ZPuggisch/ & as the almost inevitable 
comments about the military non- technicians who blocked 

things." According to a writing by Dr. Lie&knecht, of the 
Army Ordinance, Developing and Testing, Signal Branch, "This 
delay was due in part to lack of clarity in the operational 
requirements, , in part due to changes following mathematical 
researches, but in large part due to pure /technical diffi 
culties , 



19 



16 




r 



DOCID: 3560816 




J r 

Motion controls of the vsriable~notch motors are indicated 
by broken lines in the diagram. Solid lines to the "end 
plate" indicate wires from keyboard and tape printers c . 
Stote that the first variable -notch rotor never moves 
during encipherment ; Better cryptographic procedure 
would be not to allow any completely stationary rotor. 



13 • Eni 



development is worthy of study — 

the 



recapitulate, German cryptographers throughout zne war 
used a cryptographic device known as the "plugboard Enigma, 
which had a high degree of security, but was insecure 
against 'detemi:^<vdl.,;and costly Anglo-American crypt analysis*'-. 
This device was on the threshold of almost complete security - $ 
through the introduction of pluggable reflectors and/or 
the variable -notch rotors. The pinnacle of German Enigma 
development was reached with the completion of plans for 
Cipher Device 39 and the building of a very small number 
of test models . The four rotors and three Eagel in wheels, ? 

irregular interacting motions, and dual <.?nd plate p&ugglngs 
of Cipher Device 39 would have produced a machine that, 
If used properly,' would probably have racked along with 
our own SXGABA for security*^ 




45 



Gryptanalysts Schauffler ani Hauthal of the Foreign 
Office Cryptanalytic Section (Pers Z S) discussed the 
construction of a proposed new cipher machine with Willi 
Kern* engineer of the Enigma 'firm Helms be th &nd Rincke, 
Berlin, in February 1942. It was to be called "Machine 42" 
("Maschlne 42") and was to be, in effect, an Army plugboard 
Enigma with three additional rotors inserted In front of 
the plugboard--^ that is, between the plugboard and the key- 
and-light bank, The first of these three additional rotors 
was. to step each time a letter was enciphered, and the 
second and third were to be stepped by notches In the 
customary Enigma mariner. Traffic in such a machine could 
not have been solved by normal bombe methods, although 
a soecial autoscritcher can be conceived of for such 




_„ The practical difficulties wbuld be tremendous, 
so that for practical purposes Machine 42 would have been 

Machine 42 never passed the stage of theoretical 
development ,. because of engineering and procurement 
difficulties. See T-5 for details. 



secure 



17 




s ■ 



\ 



3560816 

■ V. 1 - i 
1 ■ ■■ 

1 ■ J 

\ 

■ "I* 

■ . » ^ k 

• . - . , . .. 

■ - » * ■ 

1 ■ . ■ * 

* Volume 2 • 

• * ■ ■ - 

Chapter III Teleprinter Cryptographic Apparatus 

■ ■ m i 

v . ■ " ■ . "> 

ft i 

F 

Paragraph 

■ , ■ ■s ■ ■ 1 

I * ' 

German teleprinter cryptographic apparatus was of two ' 

lain types...... ......... 14 

German, teleprinter cryptographic apparatus enciphered 

individual teletype impulses v 15 

German teleprinter cryptographic apparatus used ' ? 

mechanical wheels \ 16 

"Cipher attachment^" were insecure ......... . .......... * . . 17 

Proposed SZ~42c synchronization would have "cryptized" a 

whole radio circuit ... . v 18 

Some cipher teleprinter we're secure ............... i . . 19. 

Cipher teleprinter model used one T; time tape....... ,.20 

Conclusions; German teleprinter cryptographic apparatus 

is worthy of detailed study . . ................ , . . . 4 , . 21 

* \ ■ 

■ I 

• 1 * 

# 

■ « 

1^. German teleprinter cryp togra phic a p paratus was of 
two main typea^- German , cryptographers developed two main ' 
types of ^Teleprinter cryptographic apparatus • They were : \ 

ai Cipher attachments , which could be associated with or 
attached to any teleprinter. 

b. Cipher teleprinters, in which the cryptographic 
echanisms were integral parts of the teleprinters, 

■ , 1 

i ■ _ 

The cipher attachments were called "Schluesselzusaetze a u 
Of these, model SZ~40 (later discarded) , and models SZ-^2a and 

SZ-4'2b were insecure against Anglo-American cryptanalysis^ 

Model SZ-42c, which was designed to "cryptize" the radio circuit 
as a whole, would probably have been completely secure. 

The cipher teleprinters were called "Schltiesself ernschreib- 
aschinen." Of these, models T-52a, T-52b, T-520 (first model), 
and T~52c ( second model) were insecure against Anglo -America*! 
cryptanalysis 5 and were eventually discarded by the Germans as 
a result of their' own security studies; models T-^2d and T-52e 
could not have been solved by any presently-known methods of , 
attack. The T-^3 was a "one-time tape" cipher teleprinter and 
likewise secure if proper tapes were inserted, and if certain 
electrical elements in the apparatus were properly adjusted 

, \ ' ■ • - 

v ■ : 

r 1 " k ' 

18 



DOCID : 3560816 




v _ ^ 




Various models of all the above machines carried high-level 

communications for the Foreign Office, the Air Force, the Kavy, 

the Reich Security Office, and miscellaneous government depart- 
ments; and practically all models were used at some time or 
other by the Army down through division. 

Land-lines carried most of the teleprinter traffic, and 
land-line traffic was, of .course, not intercept;? ble by the Anglo- 
Americans. Radio links were "beamed transmissions" which were 
difficult to intercept, yet certain important Army. radio links 
employing such transmissions were intercepted. They included, 
among others, circuits between Berlin and each of the following: 
Athens, Salonika, Rome, Bucharest, Belgrade, French ports, Paris> 
Rotterdam, and Oslo; they also included circuits among corps 
,areas (Wehrkreis) in Germany itself. 

From Ultra sources, it is known that solved German tele- 
printer messages gave information in detail concerning supplies 
shipped, troop movements, police data/ and agent information. 
Important battle order information was often obtained, and 
important orders from Hitler. 

The information transmitted by German teleprinter crypto- 
graphic apparatus was therefore of utmost importance to the Anglo- 
American government and field forces during the war from an 
intelligence standpoint. The various machines themselves are 
still important, as a result of TXCOM investigations, for the 
cryptographic features they involve. - 

British cryptanalysts gave the generic cover name "fish" 
to any German teleprinter cryptographic machine, the cover name 

to the cipher attachments of the first typo mentioned in 
14, and the cover aame "sturgeon]* to the cipher tele- 

the machines of the second type. 4 ^ 



tunny 



paragrapn 
printers, 



tograph ic apparatus enciphered 

ard teleprinter o 



15- German teleprinter cr 
individual teleprinter impulses — A stan 

the so-called ^start-stop* type transmits seven impulses for 
each letter or character sent, as follows: a start impulse, 
a set of five distinguishing impulses or " bauds /, and a stop 
iianulse. Each of the five bauds is either "plu3 ir or "minus" 




(Thus, the set of' bauds 



pulse . 

depending on the character being sent. 

for "e n is plus minus minus minus minus, and the following 
sequence of impulses is sent: start, plus minus minus minus minus, 
stop. ) German teleprinter cryptographic apparatus, just as 



4 9 



Captured T-52d/e and SZ-42b apparatus are available in the 
Army Security Agency Museu] 




19 



l s 



DOCID: 3560816 





/ 



similar machines of other origin, enciphered such teleprinter 
transmissions by enciphering these five individual bauds. The 



apparatus did this by generating a key made 



up of a 

sequence of teleprinter characters, and causing the sets 
bauds corresponding to the successive keying characters to be 
combined, baud by baud, with the sets & bauds corresponding 
to the successive plain text characters . Combining was done 

according to a principle invented in 1918 by an American 
engineer named Vernam, who originated the so-called "Verriaj 
Rule" that a combination of like signs produced a ,9 ]xu-^ ,f Impulse, 
and a combination of unlike signs produced a * ? minUs r ' impulse . 
The result was, of course, a succession of sets of five bauds 
corresponding to the cipher characters. In the German tele- 
printer cipher attachments, these cipher characters were transm- 
itted without further enciphfcrment j in the cipher teleprinters, 
they underwent transposition of xbauds within characters as 
further enclpherment before they were transmitted . 



lengthy 

of 



16. German telet 



mechani 




s?~ 




aphic appa ratus used 

were 



\ 




in 

in the 
each 



all 



one- 
of 



and -42b, the "pin patterns 



11 



German teleprinter cryptographic apparatus, except 
time-tape cipher teleprinter. Around Its periphery, 
these mech <^lcal wheels had small pins which operated a switch 
or switches) as the wheels rotated. Operation of the switches 
gave In effect the plus n or "minus" impulses needed to form key 
characters. In the teleprinter cipher attachments SZ-40, -42a, 

of each of the wheels, i.e. the 
sequence of pins with respect to their being in operable or In- 
operable positions, was changeable simply by manually setting th 
individual pins Into effective or ineffective positions. In the 

(original model) and In the cipher teleprinters (S series 
except for T-V5) fche pin patterns were not variable, and were 
fixed at the time of their manufacture* The used tape and 

no cipher wheels. 



17. 



Cipher attachments" were insecure -?- The German tele- 
printer cipher attachments, or "tunny" machTnes, are of importance 
to Anglo-American cryptographers in showing them what not to do. 
All of the actually built models _ of these machines were insecure. 
Dr. Huettenhain, of the Signal Intelligence Agency of the Supreme 
Command Armed Forces (0KW/Chl\ told Dr. Yierling that their 

"security was good £ or about two years, but he evidently had 
a rather high opinion of the SZ-*2a and SZ-*2b as used with beamed 
radio, because he permitted their use past the two-year mark. . 



50 



El* p 6 



20 




■ * 



DOCID: 3560816 





i 




The SZ -40 (original model) had ten mechanical cipher wheel s, 

these 



with fixed peg patterns, 
wheels cc 



and 




ng character for the plain 
1 /wi*, ijQ 0 £ these machines 



The ten elements produced by 
bined in pairs to form one set of 5 elements , 
the set was then used as the key 
text character to be enciphered P x Only 

re built. Dr. Fricke said that since it had been ascertained 
that single messages- of l^GGO letters sent on the SZ-^O 
ginal model) could be solved, it was decided to introduce a 
machine with an irregular element in the wheel motion. 52 rpj^ 

was done by introducing the (regular), which consisted of 

12 wheels Kith changeable patterns , divided as follows % 5 



ori 



15 




he SZ-42a 



springcaesar" wheels, all of which stepped Iti unison but, irreg- 
ularly, being driven by a pair of "vorgelege" (control) wheels; 
and 5 "spaitencaesar" wheels, all of which stepped in unison 
and regularly, once for. each character enciphered . .Anglo- 
American solutions of messages sent on this machine ¥ere accom- 
plished by statistical Recovery of the pin patterns of the 
regularly- stepping wheels and the removal of their effects 
from the cipher texts; this was then followed by recovery of 
the pin patterns of the irregularly- stepping wheels and the 
removal of their effects. Dr„ Huettenhain believed that sol u- 

..the motion of the five irre- 
^ and therefore suggested 
which gave; an additional irregular control to these 
irregular wheels. This further irregular motion came from two 
sources: one source was the pattern on the first of the five 
irregular* wheels itself , ' another was the variation in the 
fifth baud of the plain-text character "two letters back" in 

,he plain text, i.e., two characters before the character 
actually/; being enciphered at the moment . This plain text auto- 
key control was optional; and because it gave rise to many 
errors it was not used often. The SZ-42b was next developed 
with a third element contributing to the irregularity, namely, 

control by the second regular { "spaltencaesar") wheel 
Hone of these ruses succeeded in preventing Anglo-American 

since the attack was to ignore temporarily 

and to remove the effects of 



4- 



a 



cryptanalysis , 

the irregularly-moving wheels, 



the 



51 



52 



In this, respect this machine was identical with that deve- 
loped by the International Telephone and Telegraph Company 
in the United States in 1931* employing 10 mechanical wheels 

and the property of pairing. 

I ho "" 



53 T 

5 \ 



31 

^5 P 19 



21 



DOCID: 3560816 




< 





regularly-moving wheels firsts Tills made attack on the irregu- 
Dearly-moving wheels possible. The Germans had evolved elaborate 
protection for the wrong end of their machine. 




1.8 • " Proposed SZ- 42c with synchronization would have 
t i z ed" a whole radio circuit*-*- The SZ-4'2c was - being de 



signed to ^cryptlze 




adio teleprinter circuit. 




ligible 



Teleprinters on this circuit were to operate at all times, 
transmitting a stream of characters forming an entirely unintel- 

essage n whenever boriafide enciphered messages were 

An interceptor would not be able to distinguish 

es sages fyom those corresponding 

Therefore 



not being sent, 
any signals representing real 

to unintelligible or random sequences of characters, 
the number, length, precedence, classification, and timing of 
messages would not be known to enemy intercept, and the circuit 
would be secure against traffic analysis. Dr. Vierling of the 
Feuerstein Laboratory was developing the crystal controlled 
synchronizing apparatus, called "gleichlauf , 11 which was to keep 

the teleprinters synchronized, regardless of radio fading and 
interference .5 

The nonsense- to be transmitted on the air whenever mes- 
sages were not. being sent would actually be "pure key" gener- 
ated by the SZ-42c. An enemy would therefore have a great ad- 
vantage in trying to cryptanalyze the, .SZ-42c. jjo one can 
state accfex'ately what results could have been obtained by_ an 

enemy given possession of tens of thousands of consecutive char 

acters of pure key, but the design for the SZ-42c appeared to 
be secure for normal operatiofcu The five regularly~moving 
wheels (spaltencaesars) of the earlier models no longer were to 
ove regularly or even together; this would have prevented the 
ethods of cryptanalytic attack, theretofore used by the Anglo- 
Americans, Dr, Huettenhain wa3 probably right in his report 
as follows; 57 

m n 

* 

"Wa Pruef 7 are at the moment carrying put a 
reconstruction in which the five righthand wheels are 
driven separately irregularly. This eliminates a cardinal 
weakness of the SZ 40 and 42, the regular movement of the 
.Spaltencaesar, and makes methods of reconstructing the 

pin arrangements impossible." - 



55 



E 14 



56e 



13 



57 



D 59 p 18 



22 



/ i 



J 



DOCID: 3560816 




A full description of 



the interacting motions involved in, the 
can be found In TICOM report s.5o 
"be 10 wheels. These 



Briefly there were to 
oved constantly unless interrupted. Inter 

ruption of motion of wheels l a 2 S 3, A s and 5, (which were the" 
-springcaesars and which moved in unison) was accomplished by* 
action of wheels 9 and 10 i Interruption of wheel 6 was 
accomplished by wheels 8 and 2; of 7 by 9 and 3; of 8 by 10 and 
^; of 9 by 6 and 5; of 10 by 7 and IV If it happened that all 
wheels became stationary (thus resulting In monoalphabetic 
eneipherment)^ the machine counted to three, and then wheels 1 

through 5 stepped automatically. > . 

The firm of Lorenz, which was developing SZ«42c with 
electromagnetic drive rather than mechanical , called their model 
of the SZ-42c machine "SK-H." They also planned SK-^5> which 
was to be identical with SK-44 except for an eleventh wheel; 
the eleventh wheel was to 3tep the machine past "dead spots/ 1 
so that the counting device used in SZ-42c for that purpose 
would not be needed. 




19 # Some 



were secure,-- There were 



in 



T-52 a/b, 0N52c "{first model), T-52e (regular), 



"cipher teleprinters" 

five main types of ciptieiTTelepr Inters developed by Ger; 
cryptographers: 

T-52d, and T-52e. ,The T-52d (probably) and T-52e (certainly) 
were secure against known methods of attack^ but were not actually 
uch In use on radio circuits . 

.All five of the foregoing cipher teleprinters were important 
because they introduced a new principle into teleprinter crypto- 
graphy: that of posltlonally transposing, as a form of super- 
enc Ipherment , the five separate bauds constituting the set 
corresponding to each cipher* character s af £er the normal 
basic encipherment had been accompli shed. 5 



or 



\ 



58 



I 57, E 14 



\ 

' F 



59 



The 



A similar principle is the subject of a U.S. patant by 
Mr.. William P. Friedman of the Army Security Agency. 
German cryptographers, however ^ brought into .actual use 
the first secret teleprinters to employ these principles in 
practice." 1 . 



* 



23 




DOCID: ,3560816 



\ 



\ 




A schematic diagram demonstrating the principles involved 

in the two processes of encipherraent, substitution and trans- 
position, is shown below: ... 



attery 



\ 



1st 
aud 




2nd 
Baud 



3rd 
Baud 



4th . 
aud 



5 th 

Baud 



Plain- 
Text 

Switches 



Key- 
Text 

Switches 



h 

"Transposition" Switches 



Ciphex 

Out- 

Put 




The foregoing diagram is not electrically accurate, but 
it is accurate in principle,, It indicates,' for example, the 
result of "enciphering the plain-text character "e" (plus minus 

inus minus) by the key*- text character "blank 1 (minus 
ninus minus minus) and passing the result through a trans 
position network as shown, with a transposition taking place 
between the first and. fifth bauds* The result is the character 



Inus 
Inus 



it 



t. 



it 



■ * 

It can be demonstrated that the security of any cipher 




teleprinter employing the foregoing principles depends upon the 
manner of generating the key- text characters, the manned of 
controlling the transposition switches, and in add it ion 6 whether 

or not the order of the transposition switches may be changed. 



2h 



i 



— 



DOCID: 3560816 





All of the T-52 series of cipher teleprinters had ten 
echanical cipher wheels, and the pegs on each of these wheels 
were set into permanent peg patterns . In the T-^2 a/b model, 

each of the five key-text switches and the five transposition 
switches was operated by one of the ten mechanical wheels,, 
The ten wheels moved regularly. The transposition switches 

could not be interchanged. The me. chine was in- 
secure because the settings of the wheels could be attacked 
Independently of one another and statistically 0 In the T-52c 
(first) model, each of the five key-text switches was controlled 
by a given combination of four of the ten mechanical wheels; 
each of three of the transposition switches iras controlled by a 
given combination of four of ten mechanical wheels; each of the 

transposition switches was controlled by a given 

six of the ten mechanical wheels. The ten 
wheels moved regularly* and It is believed that the order of 



oved regularly, 
the transposition switches was not changeable, 
the particular choice the Germans made 



Furthermore, 
sets of four 

wheels to be used in controlling the key-text switches re- 
sulted in a limited niimber of substitution permutation com- 
binations, which made solution possible. This effect was 
partially eliminated in the T-52c (regular model) and for this 
reason the regular <TI - c;0rt xTr * ° >» a #vi ™<a o 1 

Model T-52d 




changeable 



ade the order of the transposition switches 



and while eacia key-text switch and eacia transposi- 
tion switch was controlled by only one wheel, the wheels them- 
selves stepped irregularly . The movement of each wheel wa3 
controlled by the patterns of two other wheels, and interact- 
ing controls resulted. Provision was also made for the op- 
tional use of an additional plain-text control of the irre- 
gular motion. It is seriously doubted if this machine could 
have been solved, even If pure key was available from reading 

essages In depth, solely because of the Interacting, Irre- 
gular motion of the wheels. 61 



60 



61 



Inspectorate 7Al (In 7Al) discovered that the T 
breaka,ble In 19^2, and suggested alterations that 
T-52d. I 78 p II. 



Single messages might have been partially read by a crib 
matching method suggested by Inspectorate 7Al (In 7Al) 
I 78 p 12. 




25 



D 



3560816 



Model T~52e had wheel motion Identical with that In model 
T-52d. Its order of transposition switches was not changeable 9 
but each of the transposition switches and the key-text switches 

was operated by the combined pattern of a set of four wheels 

chosen for it from the ten wheels. The T-52e was therefore 

also probably secure. 

Pull details concerning the interacting and irregular 

wheel motions, the transposition of bauds, and the manner in 
which wheel patterns were combined to get pgplication of 
controls « 



are given in TICOM publications. 





20. 



odel 



-43 used one-time' tape., -- 



Cipher teleprinter _ _ 

The T-43 used a one-time key tape to supply the sequence o 
keying characters, 
the otfcier T-series 



Instead of 



cryptanalysis , therefore, 
of "random characters." 



echanical cipher wheels as In 
The T-^3 vas just as secure against 

since the key tapes. employed consisted 



In practice the key tape was generated by the running of i 
fifty -meter -long loop of random tape over and over through a 
T«52d machine, with the T-52d punching out the key tape as lonj 
as desired. The key tape was not random in a true sense, but 
It was unpredictable for practical purposes, and secure. 

A serious electrical defect in the T-^3 was discovered by 
radio engineers and corrected. This defect actually had rende; 
the T-4£ insecure. It resulted from the fact that at the Inst 
of encipherment the keying character was electrically slightly 
out of phase with the plain- text character. As a result, 
minute inspection of the cipher characters on an oscilloscope 

eparation of the composite cipher characters Into 

-text elements — : resulting in a "soluti 
cryptanalysis. 0 ^ The moral from the above story is 
plain: there are more ways than one to read a 







tographic 



a-. 



ate 



ou 



21. Conclusion: German teleprinter cr; 
ratus is worthy of detailed study, — To recap 
the Anglo-Americans were able to read German teleprinter traffic 
sent on Important Army and Air Force links as a daily pro- 
of the insecurity of the SZ-42a and SZ-42b cipher 

of the Anglo-Americans to build 

(such as the 



cedure, because 

attachments and the willingness 

Lachinery necessary for solution, 



the expensive 

British "colossus' 1 ), nevertheless the more recently developed 
German cipher-teleprinters (T- series) were completely secure 



62 
65 



I ^5, I 20, I 31 
I *5. P 15 



26 



DOCID: 3560816 




The latter units were designed along different lines froi 
lines 



taken by Anglo-American development of teleprinter 

ake definite con- 



any 

cryptographic apparatus . 
tributions to our knowledge. 



They therefore 

Their main features were 



a, 
b. 



Irregular and interacting wheel motions* 
Use of baud transposition an additional pro- 
tection, superimposing this on the basic substitution 
process. 



Furthermore, the attempted development of a cipher attach- 
ment (SZ ; -42c) for cryptizing a radio circuit, thus protecting 
it against traffic analysis as well as crypt analysis, indicated 
that the Germans were giving serious thought to all phases of 
the cryptographic proble: 




27 



DOCID: 3560816 




Volume 2 



\ 



Chapter IV - Cipher Device 41 , the Cipher Box, the 

Cipher Disk, and the "Number Printer." 

Paragraph 

* 

German Cipher Device 41 vas a secure Hagelin-type 

machine ........ . . . 22 

Security of Cipher Device 41 lay in interacting 

irregular cipher wheel motions . 23 

"Cipher Box fJ was to replace Enigma 24 

"Cipher Disk" was to be a simplification of the 

Foreign Office "Number Printer" produced non- 
random one-time pads 



o g o • 



0 Q O O 



# * o » 



26 




22. 

machine- 



German Cipher Dev ice 41 was a secure 




ipher Device 

echanical cipher device (Hagelin type) si 



uesselgeraet 




was 

ilar to the U. S. 

originally intended for use f or- 

The Gexsnan Army, Air Force, Weather Bu- 
reau, and probably others, had ordered a total of eleven 
thousand machines, 71 but only a small (unknown) quantity had 
been manufactured and put in use. Cipher Device 4l was re- 
markable for two reasons: 

a. Although it required no electrical power, beting 
operated by a hand crank, it waa compact, portable, printed 
both plain and cipher tapes, and was provided with a type- 
writer keyboard, 

b. The daily wheel settings and pin patterns were pro- 
tected against reconstruction by cryptanalysis even when 

pure key" was available. This was because even though the 
plain texts of identically-keyed messages could readily be 
obtained by well-established procedures and the correspond- 
ing portion of the keying sequence reconstructed, neverthe- 
less this reconstructed sequence ("pure key") did not pro- 
vide data whereby the wheel settings and pin patterns could 

# 

72. The Army Security Agency h 
41 in its museum. 



Army converter M-209 and was 
ward of division. 70 



it 



71 



D 59 P 2? 



28 




3560816 

T 



* 



also be reconstructed. As a consequence, no other messages 
on the same day could be read. This is not usually the case 
in other Hagelin type machines, including the U. £. Army con 
verter M-209. 



23 . Security of Cipher Dtevic e 41 lay in interacting ,, 
;ula r, cipher-wheel motions — The security of Cipher De- 
43T came fr om the interacting and irregular movements of 
ipher wheels. 



_ onstrated the 

secure in practice an otherwise not too secure 
employing the principles 
ents of wheels . 



take 

achlne, by 

of interacting and Irregular mov®- 



The 



ipher ing 

follows 



lay be 



a 



"pri 
five 



e 



it 



It had 6 



"pin" wheels, 

In cryptographic parlance, the first 
of these wheels had "kicks" 



echanical Hagelin- type 
to each other. 



spectively. 

b. Th 



of 1,2,4,8, and 10 re- 
Wheel 6 made these "kicks" positive or negative. 

_ (one turn of the hand crank) 

consisted of three elements, as follows: 

"Element 1." This element of the cycle took place if 

and only if wheel 6 had an active peg in the "motion index 
position." . If wheel 6 had such an active peg, then all the 
following events occurred: Wheel 1 moved one step. Each of 
the remaining four wheels moved one step, unless the wheel 
to its left had an active pin in its "motion index position," 

in which case each such wheel moved tvo steps. 

"Element 2." A key "kick** was generated, which was the 
sum of all the kicks of wheels which had active pegs in the 
"kick index positions." This was so unless wheel 6 had an 
inactive psg in the "kick index position," in which case the 
key kick which resulted was equal to "25 minus the sum of 

the kicks" of the wheels with active pegs. This key kick 
was in effect the "key text" or "key character" which was 
"added" to the plain text character in enc ipher ment 
cipherm€mt took place at this point. 

. "Element 3." This element of the 

in principle to Element 1, 
or not wheel 6 had 



En 



cycle was identical 
except that it occurred whether 



tion. 



The 



an 
of 



otion index posi 
purpose or this element was to insure some change 
in the wheel positions 
letter of text, if any. 



29 



1 



DOCID: 3560816 




When one compares the foregoing irregular and Interacting 
Qtions of the wheels, and the use of occasional negative kicks, 

with the simple regular motion and simple regular kick addition 

of the usual Hagelin-type machine, the reason for the far higher 
order of security of Cipher Device 4l Is Indeed apparent . 

In 1945 the British had Intercepted certain traffic en- 
ciphered by German agents with Cipher Device 41. Several mes- 



sages were read because of improper 
of the machines. The 




Its con- 



echanical working of one 
lachlne Itself, however, was not solved 
thereby, and remained a mystery until capture r 

struction. 

It Is believed by investigators that the mechanical designs 

of the Cipher Device 41 was poor but that its faults could pro- 
bably be corrected by improved engineering. Mechanical pro- 
bl ems in all likelihood prevented its wider and earlier use by 
the Germans . 

Cipher Device "4l~Z" was a modification of the standard 
model 41. It was designed to encipher ten figures Instead of 
twenty -five letters, for use by the German Weather Bureau. 72 

A model of Cipher Device 41 whi -ah would be more compact 

and would eliminate the typewriter keyboard was also under 



consideration, for use by front line troops . 




device, 
being 



out 



B ox" was to replace 

aluminum andwei 



lechanical 
pounds, was 



which involved cryptographic principles en- 



It was hoped to use this 



developed, 

tirely new to German cryptography. 

device to ren|ace the jflnigma in the German Army above the level 
of division! 1 ^ It was called the "Cipher Box" ( "Schluesselka- 
stea") ^jjd made use of the cryptographic principle of sliding 



strips J 



Col. 



of the Signal Intelligence Agency of th 



reported as follows: 
and 




Mettig, 

Supreme Comsrand, Armed Forces (OKW/Chi) 

"Field tests... had been so successful and had brought out the 
handlneas and speed of operation of the machine so clearly, that 

its introduction into the field army was ordered. As the RSHA 

(Reich Security Office) had already got in ahead with the order 
for 70,000 items, mass production was introduced." The mass 
production was scheduled to have produced at least one thousand 
devices by October 1945 and to reach a rate of 10,000 per 
onth by January 1946. 



72 

73 
74 

75 



D 59 P 25 
I 96 
I 20 

p 

1 96 



50 




Si 



DOCID: 3560816 





No Cipher Box has ever been captured 



, and the descrip- 
tions are not sufficiently detailed to do more than reveal 
the cryptographic principles involved, leaving the mechanics 
for the imagination. Fricke stated' b that "it consisted of 
a small box in the top of which vas inserted a slide rule." 
He described the slide rule as consisting of two mixed alpha- 
bets which were written in by pencil with each key change. 

Half of the first mixed alphabet was written on the up- 
per base part of the slide rule, the remaining half of the 

alphabet on the upper slide part of the slide rule. Half 
of the second 



alphabe t 



ixed alphabet was written on the lower base 
part of the slide rule, the remaining half of the 
on the lower slide part of the slide rule. The two alpha- 
bets were so written in that when the halves of the first 
(upper) alphabet were in phase with each other, 
of the second (lower) alphabet were out of phase, and vice- 
versa. 

The drawing below illustrates with sample alphabets the 
way this may have been done: 



the halves 




C £ 



5f Q 3 J 0 V X P U T & J 



LQPBQ-ftTKJB y A 1 h « D £ C J5 T K J 





Encipherment of a letter was accomplished by reading 
off the letter opposite it on the slide rule. This was to 
be chosen from whichever alphabet was "in phase" at the time 
of encipherment. In the foregoing drawing, the cipher equi- 
valent of plain text "I" at the setting shown would be W A M 
and the cipher equivalent of plain text "A" would be "I. 
Thus there resulted exactly 26 possible reciprocal encipher 
ing alphabets. 

Any sliding-strip device is secure if the successive 
settings of the sliding strip are unpredictable, 
of the Cipher Box therefore had to rest primarily in the 
manner of successively setting the slide. Dr. Pricke said 
this was done as follows: 



Security 



"Under the slide were three Hagelin type wheels 
on separate axes, in a plane perpendicular to that of 



76 



I 20 



31 



F 

DOCID: 3560816 




the slide . 



around 26. (The 



Each had a different period, 
pin settings were changeable). The slid© was pulled to the 
right against the action of a spring, and upon release &rove 
the wheels. It did not come to rest until at a reading posi 
tion of the wheels on one side the pins were all active, or 
until at another reading position on the other side they 
were all inactive. There were 26 stopping places possible, 
hut no step zero."'' 

Dr. Liebknecht of the Army Ordnance, Development and 
Testing Group, Signal Branch (Wa Pruef 7) stated:** 

"The tongue (slide) of the instrument was shoved 
by hand to the right as far as it would go, thereby 
putting a spring inside the Cipher Box under tension. 
By means of pressing a blocking notch on the top of 
the Cipher Box, one causes the sliding tongue to move 
back varying step lengths into the Cipher Box. n 




77 



I 20. 



ryptograph called the M-^0, invented by Inspector 
enzer of the Signal Intelligence Agency 

and Armed Forces (OKW/Chi), also employed three Hagelin- 
type wheels for alphabet selection. This device was con^ 

sidered reasonably secure but was never adopted. It coh- 

with 39 horizontal bars arranged around 

its periphery j 
plus the 

wheels * 




1 1 ^ — ■ 

the cylinder rotated in steps equal to one 
f the kicks given it by the three Hagelin-t 
igelin-type wheels had changeabl 
mal alphabetic seauej 



sui 



Nor- 



ces, each starting 
normal alphabel 



ribed on 26 of the 29 bar 

ummy positions." These 



alphabet, were permanently in- 

\ ; the remaining 2 bars contained 
positions." These bars represented the plain componen 
of enciphering alphabets of which the common cipher component 
was one mixed sequence written in by pencil on a fixed strip, 
so fastened on the base of the device that the bars of the 
cylinder could rotate into juxtaposition with it. The device 
was cryptographically equivalent to a pair of sliding strips, 
with the plain component a normal 
component a mixed alphabet, with 



78 



alphabet, with the cipher 
the stepping contrcT s& ir- 
regularly by Hagelin-type wheels, and with dummy letters 
thrown into the cipher text whenever a "dummy bar" came into 
position. See 1-118 for fuller details. The Cipher Box was 
an improvement over the M-40, in that the small slide-rule 
construction accomplished nearly the same results as the 

cylinder construction, the Cipher Box had two 

tions" for the Hagelin«type wheels instead of 

there was provision for two 

instead of just one. 



posi- 

just one, and 
alphabets to be inscribed 



1 57 P 9 



32 




c 



i 



- 



DOCID: 3560816 




Mowbere In TICOM was it recorded whether or not the 
slide was pulled to the right after each enc ipherment , or 
only when necessary. 

Serious study of this device has not been undertaken as 
yet at the Army Security Agency . However, the Germans felt 
that it was most secure. Lt. Colo Mettig stated as follows:™ 

"The cryptographic security of this machine is very 
high and was considered superior to that of the Enigaa. 
The safety margin for the daily cipher was calculated in 
Kiw neighborhood of Jj-0,000 to 50,000 letters, whereas 
with the Enigma this margin was 20,000 letters." 80 



25. "Ci 
her BoxT*- 




er Disk" wa s 

Cipher Box 



lif ication of the 



[nlature cipher devices. The 



as it was, was 
smaller device 



the larger 
was called 



the Cipher Disk 

TICOM 

He said: 



"Schluesselscheibe . " ) 



Dr ft Liebkneeht gave 
its best description of this device. 01 




79 
80 

81 



"Oberinspektor Mender designed this machine for 
agents. The machine was not to exceed in size a shoe 
polish can. The encoding principle was similar to that 

of the Cipher Box. The equipment (consisted) of a 

rotatable inner disk and a stationary frame. The disk 
and frame had to be provided with scrambled alphabets si 
lar to the Cipher Box. In operation the inner disk was 
rotated against the frame, 
to the Cipher Box, put a 



1* 



and thereby in a manner similar 
spring under tension. By means 
of a pressure and blocking notch, the disk is returned 
in various step lengths back toward its original posi- 
tictn. In contrast to the Cipher Box, in this machine 
only control (wheels) with fixed notches were to be used. 
In the design, three control wheels to be set. from the 
outside were to be included. The number of notches was 
to be determined once an4 for all for each pair of devices 
(one for the agent and one for central office). For 
this, a hand punch was thought of for punching the notches 



I 96 

P 

See also D 57 P ^. 
I 57 P 9. 



53 




DOCID: 3560816 






According; to Mettig:^ 2 

"The security investigations on this machine by 
Dr. Huettenhain and Lt„ Dr. Stein proved so successful 
that it was decided to employ the Cipher Disk as en- 
ciphering equipment for forward (Army) units and in- 
deed for forward of Regt HQ. 11 



In Dr. Huettenhain 8 s records was found the following 
21 April 1944 



dated 



"The Chif frier department requires . 



O 6 O 




10,000 

Cipher Di3ks and 20,000 seta each of 5 pin disc blanks . " 

i ■ 

1 4 

The Army Security Agency has as yet made no serious 
study of this device, hut IX. is believed that it has only 
limited security. 

■ 

26. Foreign Office "Mumber Printer 11 produced non-ran - 

on e-time pads -- A report on German cryptographic machines 
not be complete unless it mentioned the "Number Printer" 

of the Foreign Office Cryptographic Section 

These 



wou 

"Numerierwerk" ) 

Pers Z Chi). This device printed "one-time pads." 

were used to encipher the Diplomatic Code Book (Deutsches 

Satzbuch) ; the system was called "GEE" at the Army Security 
Agency and was solved in the winter of 1944-45, 

Cryptanalysts believe that a "one-time pad" is crypto* 
graphically 100# secure, if it is made up of random additive 
or key. The emphasis must be on the "random" as veil as on 
the "one-time." The German Foreign Office Cryptographic Sec- 
tion (Pers 2 ©hi) rrtfarlooked the "random" when they made use of 
the Number Printer. 



The Number Printer looked almost exactly like a large 

The type bed carried 240 small wheels 

Each wheel 



printing "job press." 
similar to the wheels on 



The 




a rubber date stasap. 
carried a sequence of ten digits around its periphery, 
wheels were individually removable and interchangeable, 
well as interchangeable in groups. Each time the prees oper- 
ated, it printed a sheet of paper with 240 numbers on it ' • \ 
8 lines of 6 groups of 5 digits). The press could be ad- 
justed to print up to thirty sheets of paper identically, 
but was usually adjusted to print two sheets identically, 
one sheet of which became a page in a one-time "send" pad, 
while the duplicate became a page in the corresponding one- 
time "receive" pad. Before printing the next set of two 



82 



I 96 



83q 59 P 25 



34 



- — - 



DOCID: 3560816 




sheets , the machine proceeded to turn all the 240 wheels up 
one notch except such wheels as were at the moment kept 

from turning by special mechanical means « The cryptographic 
laws governing exactly whl ;h wheels paused in their move- 
ments, when end how often/ were extremely simple « In prin- 
ciple^ this was accomplished by what might be termed K non- 
turnover notches These laws were discoverable by crypt- 
analysis. The result was that, while each page contained 
numbers that were random so far as that page alone was con- 
cerned, any given position on such a page was related to 
the same position on all the succeeding pages, and this 
non-random property permitted reconstructing sequences in- 
volved on the printing wheels. Shuffling of the sheets 
before binding Into pad forms, of course, added to the crypt- 
analysts 1 difficulties, but did not prevent recovery and 
almost 100$ reading of messages . 

Mo Humber Printer has ever been captured, but TICOM 
documents contain descriptions of early models 




&^T-1282. Captured files of the Foreign Office show that 
Number Printer apparatus was purchased from the German 
firms ISase&fcienfabrik Otto Krebs, and Clemens Mueller, in 

1925, 1927, and 1953- See D-51 P 4. Similar number printer 
apparatus was offered for sale to the British Government 
on 14 June 1952 by the English firm Loranco Ltd„, Engineers, 
by a Mr , Lorant 0 who described the apparatus, showed photo- 
graphs, and stated that his firm, (Loranco Ltd.) had supplied 
Humber Printers to the German Government in 1925* 1928, and 
1932. According to Mr, Lorant, the apparatus was for print- 
ing given numbers of copies of cipher, telegrams, although; 
It became immediately apparent to the British Government 

representatives that its real purpose was the generating 
of pages of random additives . Mr, Lorant stated that Ger- 
man Government had printed 2,000,000 pages without a break- 
down, and that they kept an additional set of 250 spare 

wheels from which to choose. The British Government asked 

but apparently subsequently 

The connection between 



Mr, Lorant to submit prices, 
lost interest in his apparatus, 
the British firm Loranco Ltd,, Engineers, 
firms, is not known at this time. 



and the Gemmn 



55 




F 



3560816 



VOLUME 2 

t 



Chapter V German Ciphony 

< 

Paragraph 

» 

German enciphered speech apparatus was unsuccessful. . 27 
Experiments showed frequency inversion insecure...... 28 

Noise superimposition gave bad quality... 29 

"Time scrambling" was insecure . . ... 50 

"Big Building Block" proved too difficult to control. 51 
"Little Building Block" combined noise super- 
imposition and frequency inversion. . . . . . . 52 

Hopes centered on synthetic speech enciphered by 

. "triple wobbling" 55 

Conclusions: Germans had no usable ciphony machines. J>\ 

* 

2J. German enciphered speech apparatus was unsuccessf ul 

Telephone or radiophone transmission of intelligence, swiftly, 
accurately, and secure ly , has been a goal of cryptanalysts 
for many years, sucn speech encipherment is called "ciphony." 

German experiments with ciphony were singularly un- 
successful. No satisfactory ciphony method was developed 
at any time .90 

Dr. Werner Liebknecht, of the Army Ordnance, Developm- 
ent and Testing Group, Signal Branch ("Wa Pruef 7"), 
where ciphony experiments were undertaken, stated: 91 

» 

r "If a process giving unintelligible speech was . 
arrived at, then unfortunately it always happened 

that i the speech quality after unscrambling was no 
longer acceptable j and the process of scrambling 
was therefore unacceptable." 

Speech encipherment experiments were carried out by 
the following seven German commercial firms from 1957 to 
19^0: 

90 

I 57 
91 I 57 



36 



r 

i 



DOCID: 3560816 





X # 
2. 

4. 



5- 

6. 



Siemens and Halske* Berlin. 

Deutsche Telefon und Kabelwerke, Berlin. 

Sueddeutsche Apparate Fabriken, Berlin. 

A. E. G., Berlin. ("Allgemeine Elektrische 

Gesellschaft") 
Telefunken, Berlin. 
Dr. Vierling, Technische Hochschule, 
Hanover . 



7 



Fabrik C. Lorenz Aktieng^s* ellschaft, 
Berlin, Muelhausen, Thuer. 
In 19^3 only Telefunken and Dr. Vierling worked on speech 
enciphering, and from 19^ on, only Dr. Vierling, at his 
jaboratorium Peuerstein ("Firestone Laboratory" J at 
fibermannstadt, Germany . 

Dr. Vierling 1 s laboratory was captured almost , intact 
by TICOM, because of Dr. Vierling 1 s orders on the eve of 
surrender that none of his expensive equipment was to be 
destroyed. Ciphony and other vailed electronic researches 
were in progress at the time of surrender. Two Army 
Security Agency ciphony engineers were dispatched to 
Ebermannstadt to exploit the German ciphony research, in 
conjunction with X?. S. Navy and British engineers. As a 
result of this exploitation, plus interrogations of other 
German engineers elsewhere, It is believed the German 
ciphony picture Is fully known at least as far as concerns 
their latest experiments. 

Six main cipiaony methods had been developed by German 
engineers. These methods were called*. 



a. 

b. 

c. 

d* 

do 
f . 



Frequency Inversion. 

Noise super imposition. 

Time scrambling. 

"Little Building Block." 
"Big Building Block." 

Triple wobbling. 



Each method in turn promised to prove less unsuccessful than 

its predecessor. 



grimentg showed frequency inversion insecure «, — 




28. 



Methods of frequency inversion usually require t 
speech frequencies (from 250 cycles per second to 2,750 
cycles) be beat against a "carrier" frequency of about 
5,000 cycles. The resultant frequencies are the 
differences in frequencies; these differences are 
transmitted, ThuSj, a low speech frequency of say 300 



37 



— — 







DOCID: 3560816 




cycles would be transmitted as a high frequence of 
2,700 cycles {or 3*000 cycles minus 300 cycles) 
a high speech frequency would be sent as a low one. 

The German inverter apparatus, which evidently 



whereas 



worked along such lines, was "a large equipment of the 
3ize of a field telephone (installation! used in the 
field since the outbreak of the war. This set was 
considered safe and encouraged careless and insecure 
conversation. In reality It was possible with an 
ordinary receiver to re-establish the Impulses normally. 
The equipment was, therefore withdrawn from units In 

There are no other important references to frequency 
Inversion, and as It is considered insecure by most 
engineers everywhere, It Is likely that no further ex- 
periments were carried out by the Germans along simple 
Inversion lines. 





29* Noise su 



osition save bad Quality. — 



Methods of noise superlmposition require tnat tne super- 

imposed noise frequencies cover the speech frequency 

band width, so that the noise can mask out the speech. 

At the receiving end a noise is applied exactly equal to 
that applied at the sending end,, exactly 180 degrees out 
of phase,, so that the noise component is cancelled and clear 

m \ - ■ 

soeech remains. 



Berlin, experimented with this method fro 



Lorenz, 

1957 to 1939* and found that frequency distortion over 

transmission lines was too great, as well as that faulty 

noise cancellation gave poor speech quality. 93 

Prom 1939 to 19^3* after exhaustive experimentation, 
Telefunken (Berlin) determined that it would be Impossible 
to cancel the noise correctly, and the speech quality 
would never become acceptable. » 

an ulti'a-high-frequency radio link 
and Derna continued noise super- 
tests were also dis- 



In spite of this, 

between Athens, Crete, 
imposition tests. Results from these 
appointing. 9 1 * 

No .further details of the experiments are available 



9 2 I -96 



93 
9* 



1-57 
1-57 



58 



• -■ 



4 



D: 3560816 



50. w Time scrambling " was insecure o— Methods of 

time scrambling require that the speech at the sending 
end be recorded immediately (usually magnetically on a 
steel tape) as a means of storing it for encipherraentj 
encipherraent results from breaking up the stored speech 

into small elements (of 60 milliseconds duration in the 
case of the German devices) and transposing them 0 The 
\ transposed elements are then transmitted by radio or wire 
to the receiving station which stores them, re transposes 

them , and puts them into the receiving telephone as speech. 
These principles, for instance, formed the basis for the 

U. S. Army's AK/aSQ^l, or SIGJIP. 

The first German experiments in "time scrambling" re- 
quired a long "time-delay" in order to store sufficient 
speech for transposition, and still did not ge suit in com- 
pletely enciphered (unintelligible) speech. 95 

In order to reduce the amount of time^delay needed 

to accomplish complex enough transpositions to result 

In unintelligibility, Siemens (Berlin) attempted to divide 
the speech into three frequency bands, and scramble 
each band separately. Dr. Liebknecht said as follows? 
"Despite the large bulk of this equipment (each station 
weighed about 100-150 kilograms) this process did not 
deliver completely unintelligible speech. The device was 

never manufacture d, "96 

Possibilities of time -scrambling were brought to the 
fore again in late 19^/ when an American Mustang airplane 
was shot down and found to include in its equipment an 
American time- scrambling radio- telephone apparatus { SIGJIP) 
According to Lt. Col. Mettig of the Signal Intelligence 
Agency of the Supreme Command Armed Forces (0KW/Chi):97 



"The technical experts believed that with 
the availability of necessary equipment, it would 
be possible to solve this apparatus in 10 minutes 
The traffic was picked up on a sound track, 
photographed and through the regular division 
of the track it was possible for an expert to 
read the conversation. As a result, there was 



951-57 

96 I- 57 
97 I-Q6 



t 



59 



\ 



t 



r 



DOCID: 3560816 




a controversy over the development of a German 

version of the Mustang apparatus. Forward units 
were of the opinion that it was Impossible to 
carry out any tactical Interception of such 
traffic since they would require a large quantity 
of special equipment. Consequently they felt the 

Mustang type could safely be used until a more 
practical machine was developed* The decision on 
this matter was never taken." 

■ 

Time- scrambling devices were called "Tigerstedt" 

"after a Swedish In- 



devices by German cryptographers 

ventor named TIgerstedt). Dr. Pricke^ 



of the Signal In- 



telligence Agency of the Supreme Command Armed Forces 
{OKW/Chi),, offered the following information concerning 
the American Mustang device ;9 



11 



He had seen an American machine on the Tiger- 
taken from a Mustang. It had a 



stedt principle taken from a Mustang. 

agnetophone band which revolved between nine heads 
which scrambled the speech horizontally (i.e. In time 
This type of machine was rejected In Germany because 
you had to wait In between utterances for the machine 

to act. He himself did not think 750 milliseconds 

, but he supposed if a Ger 




supposed if a German 
the latter would 



was very long to wait 
major was talking to a general, 

find It desirable to cut him off abruptly with a 

reply." 

There is no indication in the interrogations that TIger- 
stedt devices were ever adopted and used by the Germans* 

fc * 

n 



31 ♦ "Big Building Block"proved too difficult to 
control v ~- * Since German ciphony experiments indicated 
that too much time would be required to develop secure 

for the independent 



plans were developed 
achlne which could be built quickly 

The 



ciphony apparatus , 
construction of a 

as a "stop-gap." The first of these attempts resulted in 
the "Building Block" ("Baustein"), later renamed the "Big 
Building Block" ("per Grosse Baustein") after it was 
discovered that a second and still simpler device (called 
the "Little Building Block") would be needed. 

The "Big Building Block" used the principle of "ring 



wobbling. 



Ring wobbling" was the name given to a process 



v 



98 



1-20 



40 




DOCID: 3560816 




by which the voice frequencies were shifted up and down 
the frequency scale. When they were shifted up, the 
frequencies at the top were electrically taken out of the 
spectrum and put back in at the bottom of the scale; when 
they were shifted down, the frequencies at the bottom were 
electrically taken out of the spectrum and put back in at 
the top of the scale. The process was called "ring, 1 ' 
because what went off at the top came back around to the 
bottom, and vice versa. It was called "wobbling" because 
the frequencies wobbled or shifted, by being modulated on 
a "wobble frequency" "carrier." American engineers call 
the process "re-entrant wobbling. " 

Obviously such a system needed a wobbler — an agent 
to control the amount of the wobbling of the wobble 
frequency. In the case of the "Big Building Block" the 
wobbler was to have resulted from an autokey. The en- 
ciphered voice itself, operating through a time delay 
circuit, 100 to 200 milliseconds later, provided the 
key for enciphering the following voice . 

We have on record the following epitaph;99 

"The experiment resulted in such difficulties 
in control of the receiving equipment that the 
experiment up to the present has led to no conclusions." 




32. " Little Building Block" combined noise super - 
imposition and frequency inversion .-^-" The ''Little Building 
Block ,v ("Der Kleine Baustein"} was intended to be a low- 
security speech scrambler for land- line use only. 3*00 It 
was to be secure against the human ear only. It combined 

noise superimposition and frequency inversion. Speech 

frequencies of from 300 cycles per second to 1,300 cycles 
per second were accepted by the filter system. These 
were inverted alternately by a 1,700 cycles per second 
carrier resulting in a frequency band from 1,400 cycles 

to K00 cycles; and by a 2,700 cycles per second carrier, 
resulting in a frequency band from 2,400 cycles to 1,400 
cycles. The alternations in choice of carrier for in- 
version occurred about three to six times per second, 
depending upon the volume level of the speech. Into 
whichever of the frequency bands the speech was not 
inverted, noise was superimposed. Thus if inverted 



991-57 

100 I-57; E-9 



41 




-■ 



DOCID: 3560816 




speech occurred in the 400-1400 
in the 1400-2^00 cycle band; 
the noise 



cycle band ,. noise occured 
and vice versa . Hot© that 



was not superimposed at the same frequencies as 
the speech, as in the noise superifflposition method described 
first; therefore, it could be eliminated by simply being 
electrically ignored at the receiving end, provided/ of 
course, the receiver had the appropriate apparatus. The 
receiver then would proceed to re-invert the speech, render- 
ing it intelligible. 

This apparatus was under test by Dr. Vieriing at the 
close of the wars but only a single one-way circuit had 



9 



been constructed for the tests. 



Evidently switching 



imperfections, bad filter networks, and scarcity of elect- 
rical parts, prevented its development. The apparatus was 

not complete when captured, but diagrams are available. 1° 2 



53. 
"triple 



Hope s centered on synthetic speech enciphered 

-German engineers recognized — 



wo 



as 




early as iy^y zrmz synthetic speech might prove easier to 
encipher than actual speech. Experiments were begun which 
resulted in the development. of a synthetic speech apparatus 
called "Anna" by the German engineers, and patterned closely 
after the American "Vocoder," patented by Homer Dudley of Bell 
Telephone Laboratories. The German apparatus 9 f, Anna 0 divided 



teens 
to 



of 



actual speech into eight separate frequency bands, by 
filter networks. , It produced eight carrier frequencies, 
correspond to the eight speech bands j and when the energy 
level of any speech band varied, the amplitude of the cor- 
responding carrier frequency varied in proportion. These car- 
rier frequencies , plus two more carriers each of which repre- 
sented variations in the pitch of the speech fundamental and 



whether or 
the set of 



not 
ten 



the speech 
carriers 



was "voiced" or 



it 



"whispered, 
which was then to be enciphered. 



formed 



"Triple Gobbling" was the method proposed for the en- 
dLpherment. By this process, the composite set of carriers 
(ranging in frequency from 450 to 2110 cycles per second) was 
passed through a single stage of ring wobbling much as in the 
ig Building Block; the output from this stage of wobbling 



101 



102 



E-9 

E-9 



42 




DOCID: 3560816 




was split by filters into halves, 
wobbled j 



and each was separately ping 
these two outputs were combined and passed through 

The 



a third stage of ring wobbling. The signal was then passed 
through a fixed carrier modulator which restored the scram- 
bled signal to a transmittable frequency range. 



The following are important to note: 

to have been done three separate tl; 



Wobbling was 
separate times; wobbling was to have 

been controlled by a specially built cipher machine, and 
not by an autokey system as in the "Big Building Block." 




Dr. Liebkriecht said: 10 ? 

l, A triple wobbling project is still under 
way at the Peuerstein Laboratory, but it is also 
very complicated. Through this system, con- 
densers were to be turned under the influence 
of teletype impulses from the SZ-42 enciphering. 

device, and thus the wobbling is to be brought 
about. Until now the results from triple 
wobbling have not been very satisfactory. The 
speech quality after dewobbling was very bad. n 



Excellent descriptions of the 




It is believed 



Beech filters et- 
cetera appear in the TICOM reports. 

V triple wobbling" would 

uch research could 



by Allied investigators that 

not have proved satisfactory unless 
have been carried out, especially in filter designs. 
Nevertheless, German hopes of successful ciphony 
apparently centered on synthetic speech enciphered 
by "triple wobbling." 

34„ Conclusions ; Germans had no usable ciphony 
achines. — Unless new evidence is unearthed the con- 



clusions are: Germany had no usable ciphony machines j 
and Germany probably would not have had any usable 
ciphony machines even if the war had gone on several 

more years. 



103 
104 



1-57 

E-9, E-10, E-ll 



43 




4 



DOCID: 3560816 




VOLUME 2 



Chapter VI - German "I.B.M. and Rapid 

Analytic Machinery 



German '-"-I.B.M. f< equipment paralleled ours. . 
Rapid Analytic Machines were built on simple 
and effective lines 



Paragraph 



b. 
c. 
d. 



Rapid analytic machines developed by Armed 

Forces cryptanalysts described ........ 

a. Digraphic "weight 11 recorder 

Polygraphia coincidence counter 

Statistical "depth- Increaser" 
Differencing calculator (non-recording) 
and additive tester 
e 0 Differencing calculator (recording) 
f . Likely-additive selector 
g« Simple counting apparatus 
h. Proposed "repeat finder" 
German Army and Foreign Office cryptanalysts 
experimented with rapid analytic machinery . . 



36 
37 



38 




35. German "I.B.M/ 1 equipment paralleled ours.— 



Electric accounting machines using punch cards , called 
"Hollerith" throughout Europe and simply "I.B.M. 11 (after 
International Business Machines Corporation) in America^ 
are a primary yardstick of cryptanalytic progress. By 
this yardstick the Germans measured up well. 

A chart comparing the I.B.M. equipment of the 
principal German cryptologic bureaus with that of the 
Army Security Agency (U.S. Army) is shown herewith as 
Chart HOo 2-2. (See next page.) 

From the chart It may be seen that the estimated 
total number of I.B.M. machines used by the German non- 
Wavy bureaus was less than the total employed at Army 
Security Agency; but If the Army Security Agency machines 
devoted exclusively to the attack on Japanese Army 
systems are not counted , than the German non-Kavy 

achines In general probably exceed the Army Security 
Agency machines. 



Four key punches, 2 sorters, 1 collator, 2 

reproducers, 1 multiplier, and 1 tabulator, 

i|4 



represent 



DOCID: 3560816 





OKM/4 
SKL/III 

( Navy ) 



Pers ZS FORSCHUNGS- OKW/Chl 



and CM 

(Foreign 
Office 



Cryptan- Cryptan- 



alysis 

Crypto- 
graphy 


alysis 
Crypto- 
graphy 


Punches and 
verifiers 


30 


20 

* 


Reproducers 


6 


2 

* 


Sorters 


7 


10 


Collators 


1 


2 


Multipliers 


3 


1 


Interpreters 


0 


0 


Tabulators, 


7 


6 



all types 

< 

Special 
Equipment 



2 tape- 
to-card 
readers 



Personnel 



References 



1-158 



1 compar 
ator 
counter* 
1 selec- 
tive 



1-22 



AMT 

(Goering* s 
Research 
Bureau 

Cryptan- 
alysis 



10* 



1 



0 



0 



0 



5 



? 




15 



1-2 

1-5 
I- 

1-115 
1-67 



^Estimated 

**See Chart No* 2-3, following page 50 



and OKH 

( Sup rem© 
Command 



OKL 
(Air) 



German 
Won- 

Navy 



ARMY SECURITY AGENCY 

(U.S. 




and Arm: 



Cryptan- 





Cryptan- 

alysis 
Crypto- 
raphy graphy 



- alysis 
Crypto- 



TOTAL 
at 

least 



TOTAL General " Jap Army 

canals . Code 



40 



8* 



30* 

4* 



0 



0* 



2 



? 



150_ 

1-20 

1-127 
1-152 



45 



? tape- 
to-card 
readers 



50* 
1-119 



crypto 
ranir 



Solution 
only 



20 

i 


90 


109 


35 


74 


2* 


13 


52 


10 


42 


5 


49 

■A 


85 


27 


58 




6 


39 


13 


26 




1 


4 


1 


3 


? 


0 


7 


1 


6 


3* 


14 


47 


10 


37 



- 11 card 

operated 
type- 
writers 



4 tape-to 
card read- 

presensing 



2 presets -gang- 



ing gang 
punches 



punches . 
Also spe- 
cial at- 
tachments** 



260 I 1100 



300 



Chart HOo 2-2 



DOCID: 3560816 




the total of captured I.B.M. equipment belonging to the 
German signal Intelligence organizations; these were 
captured at Zschepplinj they belonged to the Foreign 
Office CryptA^alytic Section (Pers. Z S) . Their vires 

all ripped out and plugboards missing. They were 



were an ripped 

studied briefly by TICOM 
dynamite o 10 9 Therefore 

of German use of I.B,M. 

terrogation reports , and these discuss I.B 
scantily. Nevertheless, scattered remarks 
the used to which the I.B.M. 



Team 1 and then destroyed by 
practically all our knowledge 

tust come from the TICOM in- 

M. but 
indicate 



lachines were put by the 
Germans, and under what conditions. These technical 
uses were almost identical with those at Array Security 

the 



Agency, The important excerpts fro 
are given below: 



interrogations 



of 



a 
the 



Dr 



Bvggisch, of the Signal Intelligence Agency 
Army High Command (OKH/G. d NA), stated as follows 



concerning the use of I.B.M, by his agency 



.110 




. . "Some of the bigger I.B.M. machines were 
always being provided with special new wirings 

for special cryptanalytic purposes, as for non- 
carrying addition and subtraction in code work. 

Most of the tasks, however, consisted of the 

usual statistics (digraphs, trlgraphs, M chain" 
statistics, M column" statistics, and of simple 
figure calculations, e.g. in work on Hagelin 
Machines). But, as a rule, no tasks were under- 
taken which could not have been carried out bv hand 
by perhaps 100 people in a reasonable time.' 11 



1 



b. Evidently Army code problems (usually problems 
of finding messages in depth) were turned directly over 
to the I.B.M. section. An interrogation report stated: 112 



n A new (Russian) code came in October 19^1* 
and depths were less thereafter. Buggisch and 

other mathematicians were withdrawn from this 

and he states that the 

over largely to the I.B. M. 



work in November 19^1* 

handed 



problem was 
section. 1 ' 



109 i-i 

UOi-6? 

UlAt the Government Code and Cypher School the basis 

20 to 25 persons. , 



was 
1121-58 



46 




DOCID: 3560816 




c A complaint by Dr„ Buggisch on the way I.B.M. 
mishandled some of its more specialized statistics was 
recorded in one report as follows t 11 ^ 

"The breaking of cipher texts (without crib) 
is possible when the pin arrangement of the pin 
wheels can be discovered from column statistics 
of the cipher text •.•.The calculation is carried 
out with an I.B.M. 



wiring ■ As mistake 



lachine provided with special 
were frequent and the time 
required was considerable, the construction of 
special calculating machines for this purpose N 
was proposed. 1 ' 



(It so happens that I.BoM. is not well adapted to solution 
of the Hagelin machine* as the Army Security Agency, U. S. 
Army, has itself found out. The number of operations 
required to furnish all necessary statistics by the 
I.B.M. method allows for too many handling errors.) 



c 

5 




■ 

d, A further reference to the German Army use of 
I.B.M. is made with reference to a double transposition 
used by the Allies in Italy in February 19^5. Such 
messages included times of origin in their plain text, 
with such times of origin first enciphered by digraphs 
involving infrequent letters. (These enciphering alpha- 
bets never changed . ) The whole messages were then 
subjected to the double transposition m cipherments. 
The times of origin were seldom more than half an hour 



times of origin were seldo 
before the times of sending, so the 

"crib into" 



Gers 



formation they could 

they had broken the digraphic substitution, 
cribs were at least four letters long, and in 



ans had in- 
the cipher text, once 

These 



hort 



essages could almost always be placed accurately. 

Corporal Clemens Schuck of Inspectorate 7Al (in ?Al) 
stated as follows :11* • 

"A four letter entry would thus be obtained. 
Such a combination would be run through all the 

possible widths on the I.B.M. machines. The 

time required to break these messages was one 
to five days, depending on the number of men 
and machines available." 



11*1-80 



47 



- M — - 



DOCID: 3560816 






e. Some of the I.B.M. machines the Ar: 
ntly not working too well. The 



learned fro; 



following 



p. Fricke, when he discussed the making 
ian Army of some of its own keys and 

tables: 13 ^ 

"Daily changing trigraphic substitution 
tables were introduced (by the German Army) . 

They were made at fir3t by I.B.M The 

section moved to Weimar late in the war, and 
there the machines were so old and out of repair 
that they made too many mistakes in the tables/' 

As a result, Fricke had the tables handset by a 
printer. This later method proved more efficient. 



* * 




f , Specialist Voegele, discussing the use of I.B.HI 
by the Signal Intelligence Agency of the Commander in 
Chief of the Air Forces (Chi Stelle Ob d L), stated as 
follows concerning June 19^2 Allied air traffic s^ 1 

"The breaking of strip traffic was subject 

to time lags of two months before the receipt 

of I.B.J59. machinery, but only two to four weeks 
afterwards/ 1 

According to another report by him I.B.M. was used in 
"brute -forcing, 11 or the discovery of depths by double 
repeats o 1^7 

g. I.B.M. was used in a "brute force 1 ' method applied 
to the British Haval Cypher "to find double repeats at 
intervals up to 10," by the Signal Intelligence Agency 

of the Havy High Command (0KM/5 SKL/lIl), according to 

Oberregierungsrat Tranow and Graduate Engineer Schmalz.l^ 
I.B.M. was also used by them to provide a catalogue of 
differences, repeats, and double repeats," and most 
interestingly, "reciphering of captured subtracter 
groups." By this last was meant that captured additive 

was applied^to known high-frequency unenciphered code 
groups, to obtain a catalogue of likely enciphered code 

groups against which messages could be tested--a key 
finding technique often used at Army Security Agency . 

116 I-119 

117 I-152 , 
118 I-146 



48 



» 



- 



DOCID: 3560816 






) 



h. A "baby brute force (index of single hits 
between messages known to be from approximately the 

same part of the additive tabled was also carried out 

by I.B.M. in connection with British codes, 

I. Senior Specialist Tranow and Graduate Engineer 
Schmalz stated as follows • 119 

"Five per cent of our I.B.M. capacity was 

devoted to producing our own cipher cystems, 

We constructed reciphering tables, substitution 

tables* and the Signal-Tafeln, e.g., reciprocal 
2-letter tables, 3- and 4-digit figure tables. 
The number of cards needed for each substitution 
table was one set, for 2-letter table 
26 x 26 s and for the 5- and ^ -figure tables 

was 1,000 and 10,000 respectively." 

36 . Rapid Analytic Machines were built on simple 

and effective line s . — Just as in the United States, 

crypt analysts in Germany felt the need in special cases 
for more rapid means of searching, comparing, and other 
wise statistically treating code and cipher texts than 
hand and I.B.M. methods could offer. They developed a 
series of teleprinter tape devices, employing photocell 
readers, which accomplished these tasks speedily, in- 
expensively, and very practically. Such machines may 
be called rapid analytic machinery/' They differed 
from ra 
States 
(paper) 



pid analytic machinery developed in the Unit* 
In that in general they employed teleprinter 



than 



it is true that the first German film device was in 
process of construction; it was almost identical to 
our "Tetra -Tester, n and 

___ . . _ __ % 



vuljl i^w-a-^ow, and had an estimated speed of search 
of 10,000 letters per second, as against the actual 
speed of the Tetra-Tester of 5>000 per second. 

i 

In comparing the states of development of German 
rapid- analytic machinery with American, it might be 
said (loosely) that the German scientists were a year 
and a half behind the Americans. Development of rapid 
analytic machinery was done almost entirely by the 
Signal Intelligence Agency of the Supreme Command Armed 
Forces (OKW/Chi), and this mainly as a result of security 
studies. The special Cipher Security Section was formed 

119i-i46 

kg 



DOCID: 3560816 





within OKW/Chi in 19^0, later being put under control 
of Dr, Huettenhain. Interrogation of Dr. Huettenhain 

revealed : 1 2 0 

i 

ir By 19^1 it had become clear that machines 
would be necessary for the dual - offensive and 
defensive - task of research, but engineers vere 
not obtained until 1942 , .when the following vere 
appointed: Two graduate engineers: ROTSCHEIDT 
(formerly with Siemens) and JENSEN (who came 
directly from school), both telecommunications 
experts. (These are now thought to be in the 
South); three working engineers, TODT, SCHAEFFER, 
and KRACHEL (with a Technical High School Training), 
who were decidedly subordinate to Rotscheidt and 
Jensen; and twenty-five mechanics., 

"They decided to use I.B.M, wherever possible, 
but it was found that I.B.M. machinery was not 
suitable for all problems, and auxiliary decipher- 
ing machines were developed as the occasion arose. 
Special problems were laid before the engineers, 
and they were told f This is what I want to do, 
how would you do it? 1 The machines which, resulted 
were built in a more generalized way than the 
immediate problem demanded so that they could be 
of use again. " 

As a result the following special machines were developed: 

a* Digraph "weight" recorder. 

b. Polygraphic coincidence counter. 

c. Statistical 'depth increaser." 

d. Differencing calculator (non-recording). 

e. Differencing calculator (recording). 

f . Likely additive selector. 

g. Simple counting apparatus. 

h. Proposed repeat finder. 

Chart No. 2-3 herewith, compares these rapid analytic 
achines, developed by the Signal Intelligence Agency of 
the Supreme Command Armed Forces (OKW/Chi), with those 



owned by the Army Security Agency. 



12d M1 




50 



_ 



_ 



DOCID: 3560816 

1 




57 • Rapid analytic machines developed b£ Armed 
Forces crvntanalysts described . --The main features of 



the rapid analytic machines developed "by the Signal 
Intelligence Agency of the Supreme Command Armed Forces 
(OKtf/Chi) were as follows: 



or 




I 



searc 



weight 1 recorder . --The "Bigr&mm Suchgeraet 
apparatus," if as a device for making 
frequency evaluations of digraphs and recording the 
evaluations* It cost approximately $5^800,00^1 and 

was the most expensive rapid analytic machine owned by 

the, Signal Intelligence Agency of the Supreme Command 
Armed Forces (OKW/Chi). 



It 



was used to solve the Japanese two-letter trans- 
posed code (J-19, or "Fuji") "and the machine would find 
a solution in less than two hours. "122 it did the work 

Huettenhain/ 12 ? "The 



eteoro- 







of twenty people, according to Dr. 
tachine was once used for work on an English 

logical cipher, figure traffic employing a stencil, when 
Huettehhain liaised with the Air Force Weather Service. 
They were allowed to use the machine/ 1 12 

r '* 

The digraph "weight" recorder consisted of: two 
teleprinter tape " reading heads, 11 a re lay -bank inter- 
preter circuit, a plugbog£d "weight" assignor^ and a 
recording pen and drum.l 

■ 

Each head read its tape photoelectrically^ at a 
speed of 75 positions per second , 

The interpreter took the two impulses from the 
reading heads at any given moment, and translated them 
from two separate letter impulses into one digraphic 
impulse, which it sent to the plugboard. 

The plugboaLrd contained 676 jacks on its left side, 
representing digraphs; these could be wired at will to 
any jack in any one of five different 3ets of jacks on 
the right side of the plugboard, these sets representing 
"weights." Thus on the plugboard, any digraph could 

121 D-60 





125 

125 



1-3.1 

D-60 

1-31 

1-37 



51 



: 3560816 



be assigned any integral weight from 1 to 5 by simply 
plugging the digraph to the weight; unplugged digraphs 
had the value zero . A sketch of the plugboard follows ; 




In the foregoing sketchy for illustration, the digraph 
DE was given the weight 5* the digraph IL the weight 2, 
the digraphs PC and OX were each given the weight r. 
All other digraphs had the weight 0. 



The recording device was in effect an undulator. 
It consisted of a paper drum revolving at an even rate 

under a pen which in turn moved on a spindle across the 
drum. As a result the line traced by the pen was a 
cylindrical spiral. Undulations occurred in this spiral 
however, wherever a digraph occurred with a weight other 
than 0. The heights of the undulations varied directly 

52 



* 



D: 3560816 



7 



with the weights assigned the corresponding digraphs. 

This device was said to have made solution of a 
single transposition easy. Such solution is a familiar 
process to most crypt analysts, requiring much trial and 
error,, A message under study must, in effect, he broken 
into likely columns and these matched against each other, 
with the resulting digraphs being examined for their 
"goodness 0 to determine whether or not such matches are 
probable. If 3 for Instance, the message is broken Into 
sixteen columns, there are 1,307,67^268,000 (factorial 
15) possible matches, but these are attacked of course 
by successive steps: that is. one column is tried against 
each of the other fourteen and the most probable com- 
bination selected before proceeding further; with this 
pair as a basis, another of the remaining thirteen columns 
is selected to add to the left or right of the initial 
pair, and so on, 

It is assumed that the German digraphic weight recorder 
was used in the following manner to $olve such single- 
transposition problems: 

Two duplicate teleprinter tapes were punched, corre- 
sponding to the message to be solved, each tape then 
being formed into a loop and one loop being made, one 
space (or more) longer than the other, so that as they 
revolved through the tape reading heads they would r slide" 
relative to each other. Digraphic weights, probably 
logarithmic in nature, were then plugged up on the plug- 
board and the machine started. The result would be an 
undulatory graph indicating, digraph by digraph, for 
every possible juxtaposition of the whole message against 
Itself, the probability of a ,? good match' f at each point 
along Its length. Careful Investigation of this graph 
would thus show visually (by dense areas of tall undulations) 
those positions where 1: good 1 matches occurred, and the 
limits in length of each such good match — that is, the 
length of the columns involved. 

r 

The German digraph weight recorder was therefore 
quite different from the Army Security Agency 1 s 'felectro- 
mechanagrammer, " which also was designed specifically to 
solve the Japanese J-19 code. The American machine ran 
a deck of I,B*M. cards representing the message under 
study through an I.B.M. tabulator, with a specifically 
chosen section of the message (representing a definite 
column) wired up on the plugboard; digraphs were weighted 

4 

\ 



# 



with ten logarithmic probability values (ranging fro: 
0 through 9; and totals were printed, rather than 
individual weights being recorded separately as in the 
German digraphic weight recorder. The American machine 
took about four minutes per section to calculate and 
print the results. If the sections of text chosen fro: 
any given message were well chosen from a cryptanalytic 
viewpoint, the American machine proved much faster than 
the German machine, because the print bf totals was 
easier for the cryptanalyst to analyze than. just the 
individual values listed by the German machine; but if 
the sections of text were not well chosen and no true 



columns were included in the choice, 
machine had the 



then the German 



juxtapositions quickly, 
in the data. 



advantage, since it recorded all possible 

and all true matches were included 



The German digraph weight recorder could also be 
used to advantage to locate coincidences between messages 
The digraphs aa, bb, cc, . ... zz, could be plugged up to 

the value 1 and all other digraphs left unplugged. Then 
when two message tapes would be run against each other, 
coincidences would be shown by the undulator. Such an 
arrangement would be especially valuable in revealing 
interrupted repetitions. 



b. 



ft 



Polygraph coincidence counter . — The Saegebock, 
or "Sawbuck, was a machine for recording" the frequency 
of polygraphs occurring within one message, or for count- 
ing po^ygraphic coincidences between messages .126 

was especially useful for work on periodic substitutions. 
Polygraphs could be of any size up to and including 1P7 
decagraphs. The machine cost approximately $1,200.00. ' 



The apparatus consisted of two teleprinter-tape 
"reading heads," a "calculator" (not described), and 
different "recorders." 



ten 



Each head read its tape photoelectrically and had a 
speed of 75 positions per second. Each recorder comprised 
a pen which recorded dashes on a paper strip 20 inches 
wide, making a short dash whenever the recorder received 

an impulse from the calculator. The short dashes com- 
bined to form dashes of varying lengths. One recorder 
was assigned to "count" single letters, another to 
"count" digraphs, another to " count n trigraphs, and 
so on, up to ten. 

126 

1-37, 1-31. The Germans adopted cover names for many 
of these devices, and these names were apparently not se- 
lected at random; but like ours, were dferived from char- 
acteristics of tfye devices. The cover name "Saegebock" was 



probably so derived. 
^ f D-60 - \ 



5* 



- 



— 



DOCID: 3560816 





The machine worked as follows: if it was desired to 
record the number of polygraphia coincidences occurring within 
one message ; two duplicate tapes corresponding to the message/ 
were prepared as described above in connection with the di- 
graph weight recorder, the looped tapes then being inserted 
in the two reading heads and the machine started. During the 
first revolution of the loops, each recorder would make a short 
vertical stroke every time a coincidence of the length assigned 
to that recorder occurred between the tapes. Thus, if there 
were ten digraphic coincidences between the tapes during the 
first revolution, then recorder number two raa'de ten small 
strokes, each above the other, so that a line ten units high 
resulted; if there were four trigraphic coincidences, then 

recorder number three made four strokes, and so on. 

All the recording pens then returned to the zero posi- 
tion and the paper in all the recorders moved along one step 
automatically, to be set for the next revolution of the tapes, 
wherein the tapes were of course at a different juxtaposition . 

A polyalphabetic substitution of period seven being 
studied might therefore have given a chart of single letter 
coincidences at the different justapositions of the tapes, much 
as follows: 




Highest single letter coincidences in this sample are indi- 
cated at intervals of seven, the causal interval. 

To record the number of polygraphic coincidences between 
two different messages, a tape would be punched for each 
message, and similar procedure followed with these two differ- 
ent rather than duplicate tapes, as in the first case. 

Drs'. Huettenhain and Fricke did not identify the specific 
cryptographic systems the polygraphic coincidence counter 
was designed to attack. Dr. Huettenhain stated, however: 12 ** 




128 



1-51 



\ 



55 



\ 



DOCID: 3560816 





ir 



The problem was to determine the periods 
in short periodic substitutions by finding the 
distances between repeats in a message . „ . .It 
{the counter) could also be used to find two 
enigma messages in depth. 



11 



The foregoing 

"Fasen Suchgeraet (Perioden) , " or 
(Periods)." 



achine was one of a class called 

"Phase search apparatus 



c, Statistical 
or "Tower c 




"depth-lncreaser . " — The "Turrauhr, 1 ' 
was a device for testing a sequence 



of thirty consecutive cipher letters statistically 
against a given "depth" of similar sequences, to determine 
whether the former belonged to the given depth. 129 It 
was used "primarily for work on the U.S. strip cipher, 
when cribbing which was generally employed was impossible. "150 
It cost approximately $1,000.00.121 

The apparatus consisted of a single teleprinter tape 
reading head (speed 1 1/2 symbols per second); a storage 
means, by which any one of five different scores could be 
assigned, on a basis of frequency, to each of the letters 
in the 30 separate monoalphabets that resulted from the 
50 columns of depths & distributor that rotated in syn- 
chronism with the tape stepping, and selected which set 
of 30 scores was to be used as basis for evaluating the 
successive cipher letters; and a pen recording device. 

i 

The machine was used somewhat as follows: 




Firsts several sections of cipher text, believed fro: 
statistical study to be enciphered with the same set of 
strips and on the same generatrix, were superimposed 
properly. As a result, the letters within columns fell 
into successive and separate monoalphabets with character- 
istic frequencies, a new section of 30 letters of cipher 
text would have to "match" these alphabets, that is, show 

number of coincidences with the 



a greater than, rando; 
before it could be added to this depth. 



The machine was 



used to test the goodness of such a match. Weights were 
assigned each letter in each of the basic thirty alpha- 
bets, depending on the frequencies therein, and these 

"stored" in the machine. 



weights were 
study was punched on tape; 

12 9i-20, 1-57 



A message under 
the tape was run through the 



130 
131 



1-31 
D-60 



56 



DOCID: 3560816 

I 

* 





machine; the machine read the cipher text in sequences 
of thirty; for each sequence it applied the proper weights 
to each of the letters by choosing the weights from the 
thirty alphabets in succession; it recorded the total 
weight for each sequence by strokes of the recording pen, 

A long resultant stroke meant a great total weight; a 

sequence giving a long resultant stroke probably there- 
fore belonged to the basic set of superimposed sequences. 

Dr,. Huettenhain and Dr, Fricke, of the Signal Intelli- 
gence Agency of the Supreme Command Armed Forces (OKW/Chi), 
in describing the statistical depth-increaser stated that 
it had a photoelectric reading head. 152 in view of the 
also-stated speed of 1 l/2 symbols per second, which is 
reasonable considering the probable slowness of the dis- 
tributor, a photoelectric head hardly seems likely, and 
it is believed that actually a standard teleprinter read- 
ing head was used. They stated that "provision is made 
for 5 different scores, which seems reasonable, although 
a written description of the machine found in Dr. Huetten- 
hain' s papers indicated that 20 scores were possible „ 

which seems unreasonable. Drs. Huettenhain and Fricke 

also stated: 

"The cipher text passages already recognized 
as on the same key are stored in the calculating 
apparatus of the 1 tower clock* as a basis on whicfr 
to start; and in such a way that for each of the 
substitution alphabets the elements receive different 
scores according to the frequency of the cipher texts. 



It is believed this storage was done by hand after collection 
and examination of the cipher text, rather than mechanically 
bj a huge and unnecessary bank of relays, as might be in- 
ferred from their statement. 

* 

The machine was named "Tower clock" because it ticked 
after each set of calculations. Presumably it could be 
operated by the cryptanalyst himself. 

d. Differencing calculator ( non-recording ) 

additive tester « — This machine TGerman name not known] 

manually-operated device designed to assist additive 
recovery in superenclphered code problems, by speeding 
the differencing of depths of super-enciphered code groups 



152 



133 



1-37 

D-60 




5T 



DOCID: 3560816 




and the trial of likely additives thereon. 15^ 
approximately $40.00.155 

a™™ ™« „ 0 ften called the 



It cost 



C • R » 



It was identical In its function to 
the U.S. Havy T, CXDG~CM-10ADW." of ten called the "N 
differencing calculator." The German version had a capacity 
of thirty 5-figure groups, as against the N.C.H. capacity of 
twenty. The German device was much slower to operate, though 
far simpler in construction. 156 

* 

The German differencing calculator consisted of five small 
metal rods arranged vertically and side by side. Down each rod 

metal "rollers 



were 



31 s 
the 



tall 



, each roller carrying °on its perl 
phery the sequence of figures 0, 1, 2, 3j ... 9- A skeleton 
sketch of the machine, with its cover removed, is shown, on the 
following page, just as drawn by Dr. Huettenhain.157 



its 



The 
rodj 



top roller of each rod was fastened permanently to 
each of the lower thirty rollers was rotatable in- 




dependently on its rod so that it could be set at will to any 
of its ten possible positions. Each of the five rods revolved 
at will, carrying all of its thirty-one rollers around with it 
simultaneously. The apparatus had a lid which when closed re- 
vealed only the one figure at the center of each roller. (In 
the sketch, if the lid had been closed, the five rollers across 
the top would have indicated the five-figure group "00000," the 
next row of five rollers would have indicated the group 
"13870, ff the next row, "44651/' and so on.) 

■ 

Differencing a depth of 5-figure enciphered codegroups 
was a simple process with this machine. The five rods were 
locked into position with the top (fixed) row of rollers 
reading "00000. * Then the first enciphered code group in 
the depth was set up on the next row of rollers (marked row 

in the sketch) then the second enciphered code group 
set up on row "2; M the third enciphered code group on 
"3," etc., until all the enciphered code groups 

Then the five rods were unlocked. 



"1" 



was 
row 
set 



were 



up 



To subtract the first enciphered code group (appear- 
ing in row "1") from all the others, all one now had to 

fa 

^^Arrny Security Agency constructed a differencing calculator 
in 19^3 identical in principle to the German device. It was a 

devices 




rough 
were : 
museu; 

137 



odel and* was not perfected because the H.C.R. 
lade available. It is now in the Army Security Agency 



1-37 



58 



r 



DOCID: 3560816 

f 

i 




i 

t 



59 



D: 3560816 



4 



do was to rotate each of the fiv§ rods until the rollers 
In row "1" read "00000." The numbers appearing in all 
the lower rows no^ represented "differences . " These 
differences could now be looked up in "difference tables," 
and the most probable unenciphered paira of code groups 
they represented be noted down for trial — an analytic 
process familiar to all cryptanalysts. To "try" one of 
these likely unenciphered groups with the aid of the 
machine , all one had to do was to rotate the five rods 
until it appeared in the window instead of the enciphered 
code group supposed to be representing it; immediately 
all other rows represented the consequences of the assump- 
tion, and the very top row (above the row marked "1") 
represented the enciphering "additive." 

> ► 

\ 

This device could be operated by the cryptanalyst 
himself at his own desk, 

e. Differencing Calculator ( recording ) . — This machine 
which the Germans probably called the ' Dlfferenzen Rechen- 
geraet," or "Difference Calculating Apparatus/ 1 was designed 
to compute a "flag of difference^ for a set of enciphered 

code groups and to record this flag. 138 it consisted of 
two teleprinter tape photoelectric reading heads, a set 
of calculating relays, and a recording electric typewriter. 
The speed of the whole machine was limited to 7 symbols a 
second by the typewriter speed, with time out for carriage 
return and line feed. It cost approximately ^SOO.OO, 1 ^ 

This machine worked as follows: the figure groups 
between which differences were to be made were punched onto 
a tape. A duplicate of the tape was made, with one blank 
group additional. The two tapes were formed into loops 
and placed into the reading heads, so that the first group 
of the duplicate tape and the second group of the original 
tape were ready to be read at the same tiime. The machine 
was then started. The calculating relays computed the 
difference (modulo 10) between the two groups and the 
typewriter recorded it; thetwo tapes then stepped simul- 
taneously, and the difference between .the second and third 
was computed and recorded; then between the third and 
fourth; and so on. On the second time around, since the 
duplicate tape was one group longer than the original, 
the "offset" was automatically changed so that the first 
group was now differenced with the third group, the second 
with the fourth, and so on. In this way every group was 

i 

^D- 60 

60 

i 



DOCID: 3560816 





eventually differenced with all other groups. The flag" 
actually came out as a rectangle (rather than as a triangle). 

That is, the difference between the first group and the 

second was recorded, as also was the difference between 

the second and the first (a complementary difference). 

This gave an opportunity to ignore all "minor 11 differences 
and consider only "major" ones. 



A second version of this machine was built, in which 
one tape was left in strip form and one tape used as a 
loop. The strip tape moved through the reading head for 
one group only; this group was read and stored in the 
coraputor; the loop tape revolved; the computor subtracted 
the stored group from each group in turn of the revolving 
tape; when, the revolving tape made one complete revolution 
the strip tape moved up to its second group; this second 
group was stored in the computor and subtracted from every 
group of the revolving tape; and so on until each group 
had bee:n subtracted from every other one. 



f . 



Witzkiste 



or 



Likely - additive selector . --The 

1 Brainbox, " was an exceptionally simple device for removing 
additive from a column of super-enciphered code groups 
arranged in depth. It could be used with any four-digit 
(or smaller) enciphered code, the frequency of whose un- 
enciphered code group^^ad been discovered from previous 



removal of additives. 



Five -digit codes had to r 



the differencing calculators previously described 

cost of the "Witzkiste" is unknown, but believed less 

than $50.00. '. 



ly on 
The 



\ 



Suppose, for example, a four-digit code was under 
study, and that the following three unenciphered code 
groups were known to be high-frequency groups, from the 
removal of additive from previous depths: 0032, 0033* 
and 6748. Then if enciphered code group "0000" appeared 
in a new depth, it very likely resulted from additive 
0078, 0077 $ or 4362. Similarly, if enciphered code 
group ,; 0001 r ' appeared in the same depth, it very likely 
resulted from additive 0079* 0078, or 4363. (Note that 
additive 0078 has been indicated twice.) Any other 
enciphered code group in the depth would also have a 
set of three likely additives associated with it. A 
tally of these additives would show highest frequency 
for the most likely additive for that depth. 



140 



1-37 



61 




i 



DOCID: 3560816 




The "Witzkiste" was a device for tallying such 




likely additives photographically 
slsted of 



In essence It con- 
a "lattice-frame , " with each cell therein 
representing one of the different possible additives 
from 0000 to 9999 I & black-enameled glass plate which 
fitted under the lattice -frame and was removable; a 
light source behind both; and a camera in front. For 

the specific code used in the example in the preceding 

paragraph, the glass plate would have had the black v 
enamel scratched off at positions 0078, 0077, ^362 
(the likely additives for "0000"). 

,: 0000" appeared in 



code group 
would be placed between the 1 

and the lattice photographed, 

0078, 0077, and 4362 would be 



Whenever enciphered 
a depth, the glass plate 
.ttice and the light source, 
Only additive positions 



source 




photographed because only 
in those spots could light appear. In case enciphered 
code group "0001" appeared in the depth, the same glass 
plate would be placed between the lattice and the light 

but moved one position over, and the lattice 
would be photographed — on the same piece of film. 
Only additive positions 0079, 0078, and 4363 would be 

photographed this time. But since 0078 would now have 

been photographed twice, It would appear darker when the 
film was developed. Thus the one glass plate could be 
slid around and made to tally likely additive for any 
one of the ten-thousand possible enciphered code groups 
that might be encountered In a depthj and the additive 
whose position was darkest, after development of the 
film, was the most probable one; that Is, statistically, 
it was likely to be correct. 

The "Witzkiste" was complicated slightly by the 
fact that addltive-encipheraent addition is non-carrying 
(that is, modulo 10). In order to make the same glass 
plate find lattice do for all enciphered code groups,, 
in view of the non-carrying addition, the glass plate 
had to be sixteen times as large as it would have been 
with normal addition (each additive scratch having to 
be entered in 2x2x2x2 different positions instead of 
one) and the lattice frame had to be four times as large 
This can be explained to a mathematician by saying that 
to accomplish four-digit addition modulo 10, the lattice 
frame was spread out double size in two dimensions to 
eliminate carry over, and the scratches on the glass 

were doubled in each of four ways to make the system 
re-entrant. Such a glass plate for one additive would 
have looked as follows: 

62 



t)OCID: 3560816 




In the Wo drawings the black spots represent holes 
scratched in the black enamel of the glass plate to 
represent just one additive , In actual practice, 
many additives of course would be represented. 

With the "Witzkiste" made as above P testing for 
most likely additive was rapid and simple and as described. 
Pinal photographs could be printed out on print paper 
or projected onto a screen for study. 

Simple counting apparatus . — This, is best described 
in the words of Dr. Huettenhain as follows: 1 ^ 1 

# ■ 

"By means of simple counting apparatus it is 
possible quickly to work our statistics 9 when there 
are not more than 100 different elements 0 

"100 counting machines (Post Office counters) 
are put side by side. The text for which statistics 



1^1-27 




L. 



DOCID: 3560816 





are to "be worked, out is punched on a tape. The 
perforated strip is read and the symbol in each 
case put on the corresponding counter. The 
counters are read off and their position photo- 
graphically recorded. 

"In practice this apparatus was used with 
success within the scope of the investigations 
into the security of our own systems." 

Cost was approximately $600.00. lj * 2 

h - Proposed ' 1 repeat finder. " — This ultra-high-3peed 
machine , planned and in production but not yet finished , 
was designed to study from 20 to 25 messages for repetitions 
of five or more characters. Each message could be 500 
letters (or figures) in length. Thus study of approx- 
imately 10,000 letters of cipher text could be undertaken 
at any one time. 

Dr. Huettenhain stated as follows: 1*5 

"The 10,000 letters were recorded one after 
another as 5-unlt alphabetical symbols onto an 
ordinary film. A duplicate was made. Both strips 
were now to pass at high speed in front of a 
reader working without inertia (i.e., a photocell 
reader) . In the event of the two strips being 
completely identical for at least 5 letters, 
this passage would be likewise registered without 
inertia. 



l! The strips were to pass before the reading 
device at a speed of 10,000 symbols per second. 
Accordingly, not quite three hours would have 

been required to work through 10,000 letters. 
(10,000 x 10,000 * 100,000,000 comparisons . ) 

i ■ 

"It was also intended at first to record 
repeats that occurred thus, not yet how the 
passages read and exactly when (sic) they were . 



it 



■ 

erlcan rapid analytic machine most nearly 
comparable to the foregoing proposed device, is the 

"Tetragraph Tester," developed by Eastman Kodak Company 



142 
145 



D-60 



1-37 




64 



t 



i 



■ 



DOCID: 3560816 





for 0F-20-G, and* manufactured for both 0P-20-G and 
the Army Security Agency, This American device uses 
film; the speed past the film gate is 5,000 letters 
per second; and photocells ("readers working without 
inertia" 1 ) are used . 

w ■ 

It is unfortunate that more technical data are not 
available on the German device. Information concerning 
drive mechanisms, photocell operation, electronic counters, 
provision for accurate registration, and means to prevent 
film shrinkage while drying, all of which are of utmost 
Importance in the building of any modern photo-electronic 
analytic machine, would be useful. Even the dark room 

procedures to be used would have been of extreme interest. 

38. German Army and Foreiffi t office experimented 
with rapid analy tTcmachinery . - -Dr . Buggisch gave an 



interesting comment on the ill-fated attempt of 
Inspectorate YAl {Q£H/ln 7/VI) to build rapid analytic 
machinery, to-wit: 1 * 4 

"The limited width of the I.B.M . card was 
soon found to be inconvenient, particularly in 

counting out of repeats for the purpose of 

lining -up 2 cipher texts. The obvious solution 
appeared to be in this case to work with per- 
forated strips and 5 -unit alphabet. Orders 
were given at the beginning of 1 (?) for 
the construction of such a machine. As, however, 
Section VI only had a completely inadequate 
workshop at its disposal, and by that time it 
was already Impossible to get any more tools, 
etc., an agreement was made with the Hollerith 
[I.B.M J firm that a few rooms, together with 

workshop machines, tools, etc., in factory 
buildings at Lichterfelde Ost should be placed 
at the disposal of Section VI. An engineer of 
the name of Schiessler of the Hollerith fin 
was placed in w 

he was dressed up as a technicIan^Lieutenant 
grade), and was given a special section of his 
own. He was, in my;; opinion, pretty unsuitable 
for solving the problems set and, anyway, as far 
as his specialist knowledge was concerned, not 
even remotely comparable to the under] 

OKW/chi. The repeat counting machine 




65 




DOCID: 3560816 





was ready in the autumn of '43 (or winter 
43/44). It worked on a mechanical -electrical 
principle, the speed was not very high (I 
think a maximum of 40 pairs of letters a 
second), and there was somehow an 'idling 
period 1 ( Leerlauf ) which was very inconvenient. 
It is worth noting that* when this apparatus 

was completed, none of the specialist depart- 

tent doing practical cryptanalysis had any use 
for it, so that the question was justifiably 
raised why such an apparatus had been built at 
all. I do not think that it was ever used for 
practical tasks. 

"In the winter of 1 43/44, the workshop 
becan to be engaged on the construction of 
various mechanical aids, but they cannot be 
described as cryptanalytic machines . Thus, 
for example j a machine was made which auto- 

atically punched on Hollerith cards the 
Russian E/P traffic taken on perforated strips 

with 5 -unit alphabet. Plans were made, too, 

in the spring of 9 44 for machines which were 

to perform certain calculation tasks such as 
arose during work on Hagelin Machines; but 
those were not cryptanalytic machines either, 
but special calculating machines. I do not 
know whether work was ever started on the 

construction of these machines — the order 

was probably issued ~~ because I went to an 
entirely different department in June '44 and 

was Riven quite different tasks. In short, 
Ag N/NA had until June ? 44, and in all 



la chine 



cryptanalyti 



any 



"Things were different at OKW/Chi. There 
was no I.B.M. department there (as far as I 
know), and perhaps for that very reason they 

felt, more than in Ag N/NA, the necessity of 
developing and constructing special devices... 



Dr. Buggisch stated later that the machines developed 




at the Signal Intelligence Agency of the Supreme Command 
Armed Forces (OKW/Chi) were very satisfactory, however. 



At the Foreign Office Cryptanalytic Section (Pers ZS) 
the "Automaton" was successfully developed for mass 

- 66 



— 



DOCID: 3560816 




deciphering of American strip cipher messages . This 
was not properly a rapid analytic machine (though it 

used a istatistical principle ) but was actually a rapid 

deciphering machine. Dr. Rohrbach, of the Foreign 

Office dryptanalytic Section (Pers Z S) gave, the following 

information concerning it; 1^5 



"As was to be foreseen at the outset, 
total material 



the 




{American State Department 
essages sent in the strip cipher "0-2*5 could 
not be deciphered by hand on account of its 

immense size. The number of available qualified 
workers with sufficient knowledge of English 
was too small for that. Deciphering. . .through 
moving the strips by hand required 6-7 minutes 
on an average, so that the work ...would have 
taken a whole year, provided that 4 collaborators 
had worked on it 8 hours daily. It was, therefore, 
of the utmost importance that the automaton should 
be available for the decipherment of the material 

at the time when all keys had been worked out. 
It is not possible to describe the machine more 
explicitly within the scope of this report, but 

we should like to say briefly the following 
about the method of its workings 

"The decipherment. . .consists of two operations 
(1) arranging the strips so that the cipher text 

letters are made to lie in a row, (2) * selecting 

the line containing the true reading out of 25 
parallel lines. The adjustment of the strips that 
move up and down, so that the true reading can be 
read horizontally, is accomplished by the machine 
quite automatically, as the cipher text is touched 
by hand on the keyboard of a typewriter, or taken 
by means of a sensing device from the I.B.M. cards 

that had already been punched. Finding the true 
reading is simplified by the fact that... the most 
frequent letters in the English language (about 
80j£ of true reading) are printed in a heavy tone, 
the others in a light tone. A line consisting of 
15 letters chosen at random would contain 6 bold 
ones on an average, while the true reading line 
of 15 letters with 12 bold ones on an 



stands out distinctly 



The 30 strips 
double line 



average 

necei 



145 



isary 

for the decipherment of a double line are arranged 
side by side in two groups of 15 each for the linej 



1-89 




67 



DOCID: 3560816 




if the left-hand group is in the first movement, 
the right-hand one is in the second movement 

and vice versa. During the time when the clerk 

copies the true reading from the indicated line 
on the typewriter, the machine prepares auto- 
latically the adjustment of strips for the next 
line and performs it at the touch of a key. In 
this way the decipherment of a double line re- » 
quires barely half a minute on average. By 
means of this machine the total material could 
be deciphered within a month/ 1 




68 




DOCID: 3560816 




Volume 2 



Chapter VII. German Cryptanalytlc Methods 




Paragraph 

German cryptanalysis was generally against 

"medium grade" systems . „ 35 

Washington-London commercial radio telephone network 

conversations were solved by analysis of 

spectrograms. . » . . ; • 36 

Early Russian ciphony was solved by analysis of 

spectrograms* 37 

Some Anglo-American teleprinter messages were read . . 38 
Swiss Enigma rotor wirings were solved by cribs j 

other Enigmas were compromised . . . 39 

Traffic in Converter M-209 vas solved only by depths . 40 

B-211 machines were solved in theory only 4l 

Additive super-enciphered codes were ^solved in the 

"Usual" way • • 42 

Mihajlovic double-transpositions were solved by 

anagramming ................... 43 

Solutions of American strip ciphers involved statistical 

analysis 44 

Conclusions. 45 




German c 



tanalysis was general! 




ainst "medium 



cryptsiialytic successes were in 



Sit be termed "medium grade" or "medium security" 
systems. 1*9 These systems consisted for the most part of 
codes, either enciphered or unenciphered , the solving of 
some of which required perserverance, intelligence, and 
linguistic ability, but certainly very little of what might 
be called "higher cryptanalysis . And in their solution of 

these relatively easier systems, they developed no important 
cryptanalytic methods not already used by the Anglo-Americans 



1*9 



See Chart Ko. 1-2, Vol* 1 of this report. 



69 




r 



i 



DOCID: 3560816 




and especially in 



In higher cryptanalysil 
high-grade machine ciphers, the record of what German crypt 
analysts did not accomplish is a long one 

successful with the Japanese "red 11 
its successor , the "purple" 

United States Army Converter 



, Although they were 
lachine, they did not solve 
achine. They did not solve the 

M~134c (SIGABA), Converter M-228 
SXGCUM), the Teleprinter Cipher System using double-tapes 

SIGIBSJ nor, of course, its successor, the One-tj 
ystem JsiGTOT), no & the United States Havy equivalents* there 
of, nor the joint Army-Havy-British Combined Cipher Machine 
(CCM). If they were even aware of the e&istence of the Aaglo 
American highsecurity ciphony system (SIGSALY) is very doubt- 
ful, as not a single reference to it is to be found in any 
TICOM document. They did not solve the British Typex machine 
They apparently did not read traffic sent in the Russian B-21 
nor the French modified B-211. In their security studl 
certainly .did not develop and probably were not aware o; 

_ solving their own plugboard Enigma 

thei£r teleprinter cipher attachments . 



they 



or 



It cannot be said that this failing 
inability or ignorance. Perhaps, 




achine 



\ , Japan being Germany 
many felt it was not w<x»th while to expend the 

sary to solve the difficult Japanese "purple 




^reat 



lachlne 



^^°The German cryptanalytic failure in the case of this 

and the fact that this failure probably led higher authority 

to conclude that the machine was secure against cryptanalysis 

had immeasurably disastrous consequences upon the German war 

effort. Since the machine was regarded as secure, very im- 
portant information was constantly being given Japanese repre- 
sentatives in Europe without reservation, and this information 
was promptly forwarded to Tokyo by the Japanese, using the 
machine. Thus, from approximately February 19^1 9 when the 
United States gave the British the solution to the "purple" 
system, until the very end of the war in both hemispheres, 
Anglo -American intelligence had the benefit of authentic , 
accurat e , and timely information about conditions w 
Germany and the occupied countries, German intentions, 
results of bombing, war potential, etc. This fact was the 
central fact in the reluctance of the American high command 
to have any public investigation and disclosure of the secret 
facts and events preceding the Japanese attack on Pearl 
Harbor^ 



70 




DOCID: 3560816 




Perhaps German inability to read Anglo -America^ high-grade 

systems should he credited to our successful cryptography 
rather than to their oryptanalytlc"Tncompetence , for certainly 
our security studies showed these systems to be secure 0 Had 
these studies proved otherwise the systems would either have 
been modified or discarded. But in order to make valid studies 

of cryptographic security there must be cryp tanalyt ic c ompe - 
tence; and had the Germans been competent in this respect they 
would have realized the extent and significance of their crypto- 
graphic insecurity. However , this, too, must be added ; as 
regard the German security studies on the German plugboard 
Enigma, ^hich revealed to them no practical method of solving 
it, who can say that either British or American cryptanalysts 
would have thought of the "bomb©" as a practical answer, if 
Polish cryptanalysts had not Invented or devised the first 
crude apparatus from which the final "bombe" was developed? 

Whether the Germans deserve praise or censure, the fact 
remains that their cryptanalytic methods had no very bright 

highlights. Their ciphony breaking was not advanced. Enciph- 
ered teleprinter messages were solved only by finding "depths* 

and processing, them by long known procedures. Only the easiest 

(commercial type) Enigma was solved in actual attempts to solve 
enemy traffic. Solutions of messages enciphered by Hagelin 
machines of the M-209 type were accomplished only where mess- 
ages in depth were found as a precondition. Additively super- 
enciphered codes were solved the way additive codes usually 
are solved in America, but the U. S* Army and the U. S. Navy 
highly specialised machinery, specifically designed for the 
purpose of expediting the processing of Japanese military, 
naval « and air secret communications (all superenciphered 
codes) had no counterparts In German cryptanalytic organizations. 

The cryptanalytic highlights, such as they are, are dis- 
cussed In the paragraphs to follow, in order to make them a 

matter of record. 

* > 

i 

56. Washington-London comme rcial radiotelephone network 

conversations were solved tey analysis of Spectrograms . — Con- 
versations over the commercial radiotelephone circuits between 
London and Washington were monitored, solved, and recorded by 
the German post Office Research Laboratories in BIndthoven« 
Holland, and also by the press monitoring group (Gruppe VI) of 

m 

71 



1 

» ■ 




f 



J 



DOCID: 3560816 




/ 




Armed 



the Signal Intelligence Agency of the Supreme Command, 
Forces (OKW/ChI) located at Ludwigsfelde, about 25 miles south 
of Berlin. 15L . Some of the participants In these conversations 
are worth noting: Prime Mijiister Churchill and Anthony Eden 
when the latter was in Washington; the Minister of War Trans- 
port, and his representative; the same Minister and the British 
Shipping Mission; the Foreign Office and the British Embassy; 

the Dutch government representatives in both cities; the Russian 
embassies; the United States Embassy and the State Department. 
These radiotelephone circuits were enciphered by a "frequency 
scrambling" principle, according to Mr. K. Vetterlein, of the 
German Post Off Ice. ^52 ^he speech*frequencies ^50 cycles wide 
and the siaall blocks were rearranged in positions within the 

, to give the finally enciphered 



speech frequency spectruj 



speech* 

Simple frequency scrambling of speech can usually be solved 
by examining the spectrographic records of the enciphered speech, 
cutting out the "blocks" of frequencies with scissors, rearrange 

them by sight into r>roner order, and nasting them back to* 



Simpler yet, 

the 



ing them by sight Into proper order, and pasting the 
gether. This reveals the ^'pattern" or key used. 

if the scrambling pattern has a sufficiently lpng duration, 

rearranging can be done electrically, with the ear for a guide. 
On the Washington-London commercial radiotelephone circuit, 

scrambling and recombining of frequencies was by a pattern that 
remained fixed for 20 seconds, and then changed into another 
such pattern. There were only J6 such patterns in all, and 
then the whole, procedure repeated. Thus the grand cycle was 
twelve minutes. The German Post Off Ice had no apparent diffi- 
culty in solving this system. They built a five-bank rotary 
switch with 36 positions, drove it with a synchronous motor 
so as to step every 20 seconds, repeating every 12 minutes, and 
controlled this operation accurately over 2^ hour periods with 
a quartz -crystal-controlled oscillator. Once the German engin- 
eer wired this switch correctly to match the patterns, they 
were able to monitor transmissions 100% and receive the speefch 
Instantaneously in the clear, so that they could record the 



151 



I 84, I 88, I 118, I 190 



152 I B8 p 2 



72 




9 A 



p 



DOCID: 3560816 





_ I 



speech traffic magnetically on steel tapes . The pattern 
cycle was rearranged by the American Telephone and Telegraph 
Company (that is, the enciphering keys changed) only several 
times between April 19^2 and April 19^5s after each change it 
took German Post Office engineers "only a few hours" to recon- 
struct the new patterns and their sequence <, 153 Oscillographs , 
spectrographs, magnetophone recorders, and quart a -crystal 

oscillators for time control were available for this work, but 
well trained ears were said to have played the most important 
role in the solution. While this commercial ciphony system 
was kncran to be insecure by the United States and British 
authorities , and therefore secret matters vere normally kept 
in other channels, it is nevertheless important to our crypto- 
graphers and engineers alike to know that the Germans did solve 
it. Their total ignorance of even the existence of SIGSALY 
transmissions has already been mentioned. 

m 4 M 

t 1 

i 

/ 

37 • Early Russian oiphony was solved by analysis of 



spectrograms „ — Ra 



ephone conversations between Moscow, 



Lehingr acT, Irkutsk, Alma Ata, and Tscheljabinks, involving 

Russian Army and Peopled Coramisari&ts, up until 19^3* Here en- 
ciphered by two simple methods which were said to be easily 

solvable by German engineers at the Amy Ordnance , Development 
and Testing Group, Signal Branch (Wa Pruef 7), according to 
Corporal K&rirenberg, of the Signal Intelligence Agency of the 
Army High Command (OKH/G d HA). 1 ** These two methods of Rus- 
sian enciphering were : 

\ 

a. Inversion, employing superimposed modulation of 
several audio frequencies; and, 

b. Distortion, by artificial raising of amplitudes of 
.speech harmonics. 

# 

■ 

German scientists were able to solve these two simple 
enciphering methods by recording the enciphered speech, making 
spectrograms from the recordings, and analysing them. Evident- 
ly the voice engineers could see the results of the inversion 
and distortion, on careful inspection, and could readily identl 
fy the frequencies and methods used top encipherment . They 
tried it only a few times, according to Karrenberg, but were 
successful at will. At the beginning of 19^, however, the 



153 
15* 



I 88 p 2 

p 

i 

I 175 p 18 



73 



* 




f 



DOCID : 3560816 




simple enciphering methods were dropped by the Russians, radio 

telephone traffic networks themselves vere changed, and no 

further entry was gained by the Germans. 

Dr. Buggisch of the Signal Intelligence Agency of the 
Supreme Command, Armed Forces (OKW/Chl) studied spectrograms 
of this later unsolved* Moscow -Madrid radiophone traffic at the 
Array Ordnance, Development and Testing Group, Signal Branch 
Laboratories (Wa Pruef 7) where he became convinced that Russian 
ciphony then involved time scrambling, with the length of the 
individual time segments being 10 milliseconds each, and a ' 
synchronizing pulse occurring every .6 second, 155 The number 
of "pickup heads'" used by the Russians to obtain this time 
scrambling was reported in one interrogation to be three^So and 
In another to be four. 1 -*' German engineers vere unable to learn 
any more than this from the spectrograms. They could reconstruct 
fragments of speech, they thought, but "the validity of the 
solution did not satisfy Dr. Huettenhaln 1 s critical sense," 
when shown to him. !58 ■ Dr. Huettenhaln, who consulted with Dr. 
Buggisch, believed that some form of one-tijtne strip might have 
been used to key the time transposition, as he could find no 
period whatever in the encipherments . 




58, Some Anglo-American teleprinter messages were read .-- 

ilow much Anglo-American teleprinter traffic was read by the 

Germans is not too clear from the TIC0M reports, but It is 
doubtful If they ever solved any teleprinter enciphering mach- 
ines themselves. 

a. Dr. Huettenhaln denied that his agency, the Signal 
Intelligence Agency of the Supreme Command Armed Forces (OKW/Chi) 
did any work at all on the United States teleprinter traffic, 
although he admitted that the German Army Ordnance, Development 
and Testing groun, Signal Branch (Wa Pruef 7) passed intercepts 
to his agency. 

155! 73 



156 

157 
158 



I 75 
I 51 

I 51 



159 'I 51, P 19 



7^ 




r 




— - 



DOCID: 3560816 




b . By . Voegele stated that from, April to October 1944 




his agency, the Signal Intelligence Agency of the Commander In 
Chief of the Air Force (Chi S telle, Ob d L) Intercepted plain- 
text American teleprinter messages which concerned aircraft 
movements between American and flbrth Africa, but he mentioned 
no other non-Morse . 160 / ^ 



c. Corporal Kar^enberg stated that his agency, the Signal 
Intelligence Agency of the Army High Command (OKH/G d MA), had 
a section (Gruppe VI, Referate 2A) which 'undertook preliminary 
evaluation of British and American wireless teleprinter and 
automatic Morse traffic," and another section (Gruppe VI* 
Heferate 2 B) which ''picked up the traffic evaluated in Iteferate 
2A," 161 and that another section (iteferate I B ) charged with 
cryptahalysis of Russian secret teleprinters alfg 'forked on 
British and United States (non-Morse) systems." 162 But he made 
no references to any actual reconstruction of American or British 
teleprinter cryptographic apparatus. 

d. Russian teleprinter cryptographic apparatus may have 
been solved by Goering's f !Re search? 1 Bureau in 1943* according to 
Dr. Buggisch of the Signal Intelligence Agency of the Army High 
Command (OKH/G d Na). 15 ^ Dr. Buggisch knew no more details. 
Traffic was supposed to have stopped soon after, and the machine 
evidently went out of use. He reported that the Army did some 
work on a Russian teleprinter cryptographic machine, read a few 
depths, obtained about 1^00 letters of pure key, b^it went no 
farther. Corporal Karrenberg, mentioned above, said that Russian 
enciphered teleprinter messages, when sent in depth, were read 
by anagramming, and the corresponding keying characters recovered, 
but the machine itself was not solved. 164 Russian teleprinter 

Moscow to the 

of 



Reading 



links of which he had any knowledge were fro: 
Russian armies, and there were about eight In' all. 
the depths indicated the messages contained operational and 
reconnaissance information. Examination of the sections of key 
obtained from the readings In depth led Karrenberg to the con- 
clusion that the Russian enciphering device was similar in con- 
struction to the German teleprinter cipher attachment SZ-42 with 



160 

161 
162 

163 
164 




I 112 p 5 

p 

IF 123 p 11 

I 149 p 2 
I 64 p 2 

I 169 



\ 



75 



DOCID: 3560816 




\ 




a "motor" wheel op "motor" wheels arranged somehow to give 
a cycle of 43. None of his surmises was Investigated to ascer- 
tain its validity, it being claimed that the traffic was too 
scanty to effect a solution 



39. 
other Eni 



Swiss Enigma rotor wir 



were solved 



l"K' : type 




cribs; 
Enigma 



s were compromised , — The Swiss diplomatic 
was read regularly, probably by the Signal Intelli- 
gence Agency of the Supreme Command Armed Forces (OKW/Chi), 
although Dr. Huettenhain, who revealed this solution, did not 
state definitely that it was his agency which accomplished it. 

The Swiss changed their Enigma rotor wirings every three months, 
but the changes were not effected on the Berne -Washington link 

at the time they were made on the Beme-London link, as a result; 

duplicate messages sent by the Swiss to Washington and to London 
during the periods of changeover provided the break" necessary 
to learn the new wirings. l^o The Croat enigma, used for both 
diplomatic and military traffic, was read regularly by Inspecto- 
rate 7 /VI (IM 7 A*)* This was no credit to the cryptanalysta 
involved, however, as their problem was particularly easy: (1) 
they had obtained the rotor wirings from Konski and Krueger 
(Berlin) who made the rotors; (2) there was no end-plate plugging 
involved: (5) the rotor orders were not changed by the Croats; 
(4) the rings tellungen" (devices enabling the notches and 
alignment indicator letters to be "slid" in relation to the rotors) 
remained fixed; and (5) there were only 100 initial rotor alignments 
used by the Croats each month* 

An excellent treatise on Enigma ("K" type) solution was 

found in the files of the Foreign Office Cryptanalytic Section 
(Pers Z 3). It involved obtaining many messages in depth, 
reading these messages by solving the successive (mono&lphabetic) 
columns of superimposed text, and then applying the resultant 
cribs to recovering the wirings of the rotors* These methods are 
well-known to Anglo-American cryptanalysts, loo 



165 

166 
167 

168 



I 169 
I 51 

I 84 p 3 
T 572 



76 




p 



DOCID: 3560816 




Type* was the object of study by D*. Buggisch 

land . 



mo 



Intelligence Agency 
Armed Forces (OKW/Chl). He showed British Typex to be an 
Enigma type machine , by statistical study of 10*000 letters 

further. 169 jj 0 German 



of cipher text, but was unable 
cryptanalytic agency was able to solve it. 



40. 



in 



in 




onl 



y our 



d epths . — 
orces 



S. ATI w 

(including the Air Forces) and the U. S. Navy, was under study 
more or less constantly by the Signal Intelligence Agency of the 

Command Armed Forces (OKW/Chi) by the Signal Intelligence 
Agency of the Army High Command (OKH/G d Ha), by the Signal 
Intelligence Agency of the Air Force High Command {OKL/Ln abt 

550 and its predecessor Chi Stelle Ob d L), and by the Signal 

Intelligence Agency of the Navy High Command (OKM/4 SKL/lII). 
Many theories were developed for statistical solution of M-209 

taful. Solutions depended en- 




s 



though 



in depth, recovery or icey tnere- 

, and reading the remaining 




reading 

from, then obtaining absolute settings 

throughout 



tessages in the same day's traffic. 

the TICOM reports concerning these solutions are as follows 



a. Dr/ Huettenhain of the Signal Intelligence Agency of 
the Supreme Command, Armed Forces (OKW/Chi) stated that M-209 
depths were found by using "Fasensuchgeraet," a rapid analytic 

lachine, probably the "digraphic weight recorder" described in 
Chapter VI of this volume. 17^ 

b. pr. Buggisch of the Signal Intelligence Agency of the 

Array High Command (OKH/G d KA) gave a statistical formula to be 
used with I.B.M. machines for aiding in finding M-209 pin pat- 
terns, 
the width' 1 



This consisted of writing the cipher text out "on 



of one of the wheels, and applying a form of ,! phi" 
test to the resulting alphabets. Alphabets having distributions 
which showed the least randomness were supposed to be indicative 
of inactive pins. Br. Buggisch did not state that he was ever 
able to make the test work, and it is believed at the Army 
Security Agency from long experience with similar tests that this 
particular one certainly would not have worked. 



169 

170 
171 



I 66 



I 31 
I 157 



77 




DOCID: 3560816 




/ 



Co Lt. Muentz, of A the Signal Intelligence Agency of the 
Navy High Command (OXM/4 SXL/lII) developed a statistical theor; 
for solving Converter M-209 as used by the U 1 S. Navy, based on 
the frequent use of "Z !1 asufc word separator. 1 ' 2 This never 
worked on actual traffic. 1 ?-? Amtsrat Schultae. of the same 



Agency 



raak 



guess plain 



a 



4l . B-211 



successes with the 



ach lnes w ere solved in theor: 
rench 




.—German 
and the 



Russian B-211 were practically non-existent. Dr. Huettenhain 
said a French (modified) B-211 was captured, and believed that 
an 8 to 10 letter crib could solve the wheel settings, pin 
settings, and pluggings, if the cipher wheel wirings were known. 
A Russian B-211 was also captured and a theoretical solution 
devised, but since no traffic was received this solution was 

never tested in practice. 175 



/ 




.42. Additive super-enciphered codes were solved in the 
usual" way . .—HQ great new cryptanalytic methods were developed 
by German cryptanalysts to assist in solving additive super- 
enciphered codes. They were solved as such codes usually are: 
by superimposing identically-keyed texts (by virtue of identical 
indicators and by means of repetitions), removing the additive 
frbra the depths, and reconstructing, from the resultant relative 



the depths, and reconstructing, 

the basic code — unless the code book i 



already 



c)de values, 
known. 

a. An example of the foregoing type of solution by the 
Germans is noted in the case of their cryptanalysis of the 
British War Off ice Cypher, a 4-figure super-enciphered code 
used between Army, Corps, and Division. ..which was read during 
the campaign in North Africa in 19*0 . ^ro 



172 
175 

17* 
175 
176 



I 50 
I 6 
I 147 
I 58 

I 51 




78 



i 



DOCID: 3560816 





■ 

... b. Another example Is the Turkish. ^-figure diplomatic 

code enciphered by repeating additives, which was solved 
without regard to indicators simply by superimposing sections 
of messages at the period of the additive (in this case a period 
of 

and reconstruct the code. 



20) thereby obtaining enough depth to eliminate the additives 

Tflfinn a tT*iir»f. thft find e .178 



c 



(including 



The German Bavy's 

"British Haval Cypher Mo. 



solutions of British naval codes 

5") are perhaps the most 
completely described solutions of the foregoing type in TICOM 
publications ,!79 These solutions extended from before 1939 to 
the end of the war. Before 20 August 19*H* when the indicator 
groups were not super-enciphered, messages were lined up in 
depth by Indicators, and additives were eliminated therefrom by 
the use of "difference tables" or by guessing stereotyped texts. 
Some of the codes themselves were solved by cryptanalytic recon- 
struction, and some were captured. When the Merchant Marine code 

indicator systems became difficult, in 19^2, messages were lined 
up in depth ,by other methods . One such method was that col- 
loquially called "brute force, 11 that Is, pairs of messages were 
sought wherein at least two code groups in one message, separated 
by a definite Interval, coincided with at least two code groups 
in the other message, separated by the same interval. Such 

essages were likely to have been enciphered with the same sect- 
Ions of additive, especially if the interval was not over 10, ac- 
cording to the Germans. However, they considered "brute force" 

unreliable and used it as little as possible. Whenever sections 
of additive were already known, messages were set against these 
sections by a technique quite familiar to the Array Security Agency. 
This consisted of applying all of the individual additive groups 
of a known section to 15 or 20 of the usually most frequently oc- 
curring unenciphered code groups, and obtaining thereby a set 
of enciphered code groups most likely to occur in messages en- 
ciphered with the known additive section. If two or more such 
likely enciphered code groups occurred In a message, at an 



177^ m y security Agency trigraph, "TUK 



T1 



178 
179 



I 105 

I 93, I 1^6, I 147 



79 




DOCID: 3560816 





\ 



Interval saatching the interval between the groups of additive 
from which they were derived, then It was very likely that the 
rest of the message could he deciphered from that point on in 
the section of known additive. The ordinary cryptanalytic 
aids, such as difference tables (made by German cryptanalysts 
usually from the 200 highest-tfrequency code groups;, known and 
frequently-used addresses, spelling groups, figure groups, and 
place names, as well as stereotyped texts, aided them in aligning 
lessages and eliminating additives. By such means, depths of only 
two were often read— in fact, If the two messages were routine 

reports, "they were read without exception. "180 } 

When the British Navy introduced the "S.S. Frame 11 in December 
1943, 1S1 German cryptanalysts were able to analyze correctly 
the new cryptographic system being employed, and were able to 
read messages superenciphered In this snew system for one month* 
The German cryptanalysts were able to superimpose a few messages 
in depth, which permitted them to recover several sequences of , 
additive; they discovered that parts of one sequence of additive 
at times overlapped parts of other sequences, albeit out-of- 

phase and very irregularly; by using this knowledge to test new ' 
assumptions, and after much trial and error, they were able to 
recover and reconstruct a complete set of number tables; they 
also solved the weak December 19^3 indicator system, which 

relied only on random co-ordinates to indicate the stencil 
position; and as a result of these activities they obtained a 
fair under standing of the British "s.S. Frame". They complained: 



18? 



180 
181 



I 93 P 2 



In one type of Stencil Subtractor Frame, a stencil of 100 ... 

irregularly located apertures, each aperture 4-dIgits wide, Is 
placed on a card of randomly chosen numbers, 48 by 68 digits in 
size, at any one of 100 settings determined by a specific key, 
and the 4-digit groups that appear in the apertures of the sten^ 
cil provide additive. Parts of additive obtained at any one 
setting of the stencil will not properly "overlap" additive ob- 
tained at another adjacent setting, because of the irregular 
spacing of the stencij apertures. Thus satisfactory depths that 

can be found 1ft such a system are obtained only from identically 
keyed messages. 



182 



I 95 P 25 



80 




r 



* 



I 



DOCID : 3560816 




V 




We discovered that we had formerly had on the long 

subtracter system 1,500 starting points over a 10 day . 

period ; whereas we now had 10,000 different starting 
points on one daily table," 



On 1 January 19^4 the British changed 
as well, and soon thereafter began to use "doubly enciphered 
indicators" for the "S. S, F^ame" . The Germans, with almost 
no depths possible, and with the basic code book unknown to 
them, could no longer read the traffic . Senior Specialist 
Tranow, of the Signal Intelligence Agency of the Havy High 
Command {OKM/4 SKL/iII) stated: 15 ? 



We came to the conclusion that we could not recover 



a system of this kind within six months, without having 
the basic book. However it was clear to us that if we were 
able to capture the book, we should then be able to break 

this system in a very short time. We provided our own 
proof for this...* We constructed synthetic messages of 
our own on the pattern of the British originals. We be- 

the first trial with 200 messages a day and broke all 



gan 

of them within three weeks .... 
second trial with 100 message? 

practiced and , succeeded with a smaller number of 
in a shorter tipie . " 



We then carried out a 
The staff was much more 

tes sages 



So far as is known, however, they did not "capture the book" or 
continue solving the syste 

d. The Polish government in London used an additive super- 
enciphered code for Military Attache messages, which was read 
regularly by the Signal Intelligence Agency of the Supreme 
Command Armed Forces (OKW/Chi) until about 19^3 when the Poles 
changed their methods of obtaining the additives. The Poles had 
introduced their version of the British "S.S. Frame," at the 

suggestion of the British Government; their stencils had from 
28 to 40 randomly placed apertures, rather than 100 as in the 
British version. The German cryptanalysts, having the Polish 
code book from their previous solutions, were able, with it and 
with depths obtained by I.B.M. searches for repeats, to recon- 
struct additives, discover the irregular positions of the steng&L 
apertures, and reconstruct the stencils, and read the 



183 



essages-r^ 

each 



I 93 p 25. Even with the indicators amply enciphered, 
headway was made by German cryptanalysts in recovering relative 
starting; points. See D 25. 



184 



I 118, I 31 



r 



81 




DOCID: 3560816 




* r 



ana 




i 

Mhajlovic double-transpositions were solved b 



lag. — Yugoslavian double -transposit 




MhajlovXctraffic) were solved by Corporal Herzfeld of In- ~ 
spectorate ?Al (In 7/VI), in from one to three days.l 8 5 in 



each message, the same key was used for the two transposition 
matrices, and the matrices were usually incompletely filled. 
The width of the transposition matrices were assumed bv Cor- 
poral Herzfeld each time "with some degree of accuracy, based 



on his previous experience with 
on the same networks. 



tessages of the same length and 
This was of course a great advantage, 
since it permitted a marking off in the cipher text of the 
approximate columns of" the second transposition matrix. The 
words "GEHERAL DftAZA MIHAJLOVIC" which nearly always appeared 

as a signature, made an excellent crib because several of the 

letters were infrequent, and because these words could be 

written In as the final rows of the first transposition matrix. 

With the dimensions of the matrices chosen by good guessing, 

and with both the complete columns of the second transposition 

matrix aad the final rows of the first transposition matrix de^ 
lineated, the German corporal then tried to match elements of 

and 




his cipher text with elements of his crib, 
recover plain text and the key. The methods 

unusual. 



by 
used 



anagramming 
were not 



44 . Solution 



erican 



statistica 



American 





involved 



Cryptanalytic successes against 
p cipners were obtained by at least three German 
agencies. Dr. Rohrbach, cryptanalyst of the Foreign Office 

Cryptanalytic Section (Pers Z S), who claimed that his group 
of six cryptanalysts solved the United States State Depart 
strip cipher ("0-2") in 1945 without any previous knowledge 
concerning the general system, required over a year for solution. 
The State Department strip cipher "0-2" which he solved did not 

imination, but it did make use of the principle 
of* "split generatrices" — that is, 50 strips were chosen out of 
a possible 50 strips each day and arranged in a channel board 
according to the daily key, and messages were then enciphered by 

successively setting up 50 letters of plain text across one 

line of the strips, each time reading off 15 letters of resultant 
cipher text from the first half of another line, chosen at rando: 



l85 I 69 p 25; I 52 




8S 



DOCID: 3560816 





and 
of 



©thods of 



aining 15 letters of cipher-text from the last half 

a third line, chosen at random. Dr. Rohrbach 

solution were recorded in a detailed paper written by him at 
the request of TICOM interrogators , l8 ° and they were similar 
to the statistical methods 



suggested as a general solution by 
United States Army cryptanalysts in 

punched on I.B.M. 



the material was 



Messages were 
cards, repeats were found which indicated 
that intervals of 15 and 50 were significant 
sorted into "families" (Dr. Rohrbach defined a 
collection of homogeneous cipher material based 
same generatrix in the enciphering 
"families" were solved, as similar 




and 



on use 
the 



of the 



larger 

e solved, as similarly-keyed poly alphabetic cip 
analyzing the material "column by column." The 

many of the 

strips, and with their aid the 



remaining 



&mi 



were solved. 



.ies" and stri 

Although Dr. Rohrbach indicated in his writing 

that he had had no previous knowledge 

when he started his solution activities in November 19^2, it is 

a fact that the Foreign Office Cryptanalytic Section (Pers Z S) 

had received photographic copies in 19^1 fro; 
gence Agency of the Supreme Co 



Mill 



the Signal Intelli 
land Araed Forces (OKW/Chi) of a 
set of instructions for an earlier American strip cipher ("0-1") 

and "4 series of strips by means of which a number of messages 

could be deciphered . "187 Files of the Foreign Office Crypt- 
analytic Section (Pers ZS) captured In 1945 also contained 
photographs of two Tables of Numerical Keys for the same 
earlier State Department strip cipher ("0-1"). The advance 

knowledge of the general system given by this compromise, and ■'. 

the stereotyped beginnings that Dr. Rohrbach indicated in his 

paper were present in State Department traffic ("0-2") (such 

rictly confidential from Murphy ... . ") together with 
ate Department • s reuse of each daily key an average of 9 
throughout the year (only 40 different strip 

were provided for 365 days traffic) should have made the 

solution much easier for Dr. Rohrbach than he found it. 





186 
187 



I 89 

DF 15 P 5 



83 




.■ 



3560816 



k 

Dr. Huettenhaia of the Signal Intelligence Agency of the 

Supreme Command, Armed Forces (GKW/Chi) stated that his agency 
worked on American diplomatic strip systems, and that they were 
not aided in their work by any captures, but succeeded through 
cryptan&lysls only. iyy This statement is also at variance 



with the record, 
being handed over 
Supreme Co 



already 
fro 



/iJti 



entioned, of compromised strips 
the Signal Intelligence Agency of the 
and Armed Forces (OXW/Chi) to the Foreign Office 
Cryptanalytic Section (Pers Z S). The techniques used by Dr. 
Huettenhain are not recorded, but his Agency considered 
American strip ciphers of sufficient importance to build a 
special rapid analytic machine (the "statistical depth- increa- 
ser") for facilitating statistical solutions. 1 ^ 

According to Dr. Ferdinand Voegele, Chief Section B, of the 
Signal Intelligence Agency of the Air Force High Command ( OKL/LN 
abt 350), a strip cipher of the United States Army Air Force 
South Atlantic Ferry Command was solved before 19*3. He wrote? 0 

It was quite evident from the cipher text that 
there was a break after each 15 letters. . Accordingly 
an analysis was made on the basis of groups of 15 letters 
with the assistance of I. B* M. machines • A depth of 80 
passages of parallel construction was needed to reconstruct 

the 100 strips, 20 of which were valid in any one day.,.. 

The system was read as long as it was used. 

'In 19^3 a new difficulty presented itself. While 30 

strips were still valid on any one day, the encipherer 
could arbitrarily remove any five of the strips to encipher 

After about six weeks, some of these 

However, at the same ti 



any one message. . . . 
messages were also deciphered 

the volume of this type of traffic began to decline, so 
that finally the analysis work had to be discontinued." 



te 



later 



Techniques employed by Voegele and his assistants are not 

known. Decipherment after about six weeks" of some of the 

when strip elimination was employed, may have been 

It is interesting to 



messages, 

accomplished by the skilful use of cribs, 
note that soon after strip elimination had been introduced, 
"the analysis work had to be discontinued." 



I 84- 



188 

"^See Chapter VI of this volume. 

another device, the "automaton", was also developed 
Foreign Office Cryptanalytic Section (P#rs Z S) for 
cipher ing of a large backlog of stirip traffic. 



It will be recalled that 

the 



by 
rapid 



de- 



190 



IF 175 P 15. 



Page 84 



•- 



DOCID: 3560816 





Major Dr. Rudolph Henze, head of the cryptanalysis group 
of the Signal Intelligence Agency of the Army High Command 

(OKH/G d NA) reported solution of an American "strip 11 



the intelligence of which was 
and which, fro 



c iphe r 

lixed military and diplomatic," 
the description of the 



was actually enciphered toy Army 
than by any of the strip cipher 

This was technically not a 
Henze, since the aluminum disks 



system, and its indicators, 

cipher device Type M-9^ rather 
devices • 191 



tistake in terminology by Dr, 
of the M*9^ i&gx toe considered 

to be strips from a cryptanalytlc viewpoint .^S A soldier, 
Werner K, H. Graupe (rank unknown) reported that he cryptanaly- 
zed an American "strip" cipher (actually the M-9^) carrying 
Iceland and Carribean area traffic, while he was presumably in 
Inspectorate j/VI (In 7 /VI) in Berlin. 1 ^ He used cribs, with 
the help of synoptic tables, to determine the ,T strip M (disk; 
orders, and stated that he later believed I. M. methods 
were developed to eliminate impossible keys . According to 

the interrogator, Graupe 1! khew of what he called a 30*strip 

system, lout stated very definitely that it had never been 
solved * ,f Lt. Col. Mettig, who was the commanding officer of 
Inspectorate 7/VI (In 7/VI) from November 19^1 through June 19 1 *?* 
stated 1 ^ u ..it was eventually recognized that the main cipher 
procedure used by the Americans was the strip method whereby 25 
variously arranged alphabets were vertically laid out one along- 
side the other. In the workshop of In l/VI mechanical aids were 
constructed and with the help of the I. B. M. section and by 
noting the addresses and signatures, the various alphabets were 
recreated.- 1 



^I 112 

1 " m a 

°^Dr. Voegele, the Ail? Force cryptanalyst, considered North 
Atlantic Air Force traffic as toeing "atrip." See 1-112. 

1 93if-io7. inspectorate 7/VI w & s & predecessor of the Signal 
Intelligence Agency of the Army High Command (OKH/G d MA). 

194 I 78 p 10 



85 




DOCID: 3560816 



To auimtt&rize: German cryptanalysis of both the strip 
cipher and the apparently developed no exceptional 

methods., although it did result in the construction of two 
special rapid oryptanalytic machines , the "statistical depth- 
increaser" and the "automaton/* described in Chapter VI ♦ 

^5- Conclusion s-German cryptanalysis was very success- 
ful on lo¥ grade systems , not only because the German crypt- 
analysts were sufficiently skilled to take advantage of the 
presence of Ion security traffic, but also because of the 
failure on the part of Anglo-American coissraanders to realise 
the extent to ^hich the Germans were able to go in taking ad- 
vantage of insecure practices • / 

German medium-grade cryptanalysis vas extensive and vcrth- 
uhile^ as can be seen from the Cryptanaly tic Successes chart, 
Chart Ho, 1-2, Volume 1 of this reports but no outstandingly 
different or unusual cryptanalytic methods uere developed by 
the Germans in their medium grade solutions. 

German cryptanalysis vaa not outstandingly successful 

against systems of high-security. This saay have been not only 
because Anglo-American high-security systems vere actually of 
high-security, and were to some extent insolvable to Anglo- 
American cryptanalysts as veil, but also because the German 
cryptanalysts never became technically proficient enough to 
undertake even the solution of the less difficult of the high- 
security systems .".=.''■' 



/ 



* 



m-r - — 



/ 



86 




— 



p6Cljyf' 3560816 



Volume 2 



Tab A 



Abwehr 



General Information and References 

m 

See "Military Intelligence." 



Amy Ordnance, Develo 

(Wa Pruef 7). 



WO. 



Ger 



ent and Testing Group, Signal Branch 
This organisation developed^ engine* 
ered and tested Signal Corps equipment • It also 
did some non-morse interception. It is described ; 
in Volume 8 of this paper. 
A.E.G., Berlin. ( "Allg^m^t Elektrische GesellsohaSt") 

lan coiamercial firm which worked on speech encipher- 
ent. • ■ 

Air Force leather Service (Wetterdienst der Luftwaffe) . This 

service was charged with cryptanalysis of enemy 
eteorological ciphers. 

Allgem^ius Ele^fcrlsehe Gesellschaf t . 



German Coaanercial fir 



Mb 



which worked on speech encipherment 
Bugglsch, Staff Sgt. Dr. Otto. Cryptanalyst of Inspectorate 

fAl (l n l/Vl). Expert on German cryptographic ap- 
paratus, and on clphony matters. 

"S.S. Frame Indicator System." A TICOM publication. 
"Translation of Miscellaneous Documents from Pers 

Z S Archives." 
"Notes 



D-25 . 
D-51. 



D-57 . 



D-58. 



A TICOM publication, 
md Minutes of High-Level Mettings held at 

OKW/Chl-— Cryptographic and Administrative. " A 

TICOM publication. 

"Description of Facsimile Intercept Recorder." 



A 



D-S9. 

D-60. 



TICOM publication. 

"Hotes on Cipher Security and Minutes of Meetings ' 

held at GKW/Chi." A TICOM publication. 

"Miscellaneous Papers from a File of RR Dr. Huetten- 

hain of OKW/Chi." A TICOM publication* 
Deutsche ; Telefcn und Kabelwerke, Berlin. German Commercial 

firm which worked on speech encipherment . 

TF 20 "A Group" Reports (American Systems). 

"Detailed Feuerstein Technical Project Report Ref . 

Ho. 2 Little Baustein." A TICOM publication. 

"Detailed Feuerstein Technical Project Report. Ref. 

Ho. 3s Artificial Speech and Encoding." A TICOM 
publication. 



DP -15 . 

E-9. 

E-10. 



87 



ID: 3560816 ' 



E-ll. 



FA. 



Pes 



Dp 



"Detailed Feuers tela Technical Project Report 
Ko. 4: - Three-Fold Wobbulation and Mechanical 
Wobbulator Generators." A TICOM publication. 
"Detailed Feuerstein Technical Project Report 
Ko, 6: Synchronous cipher system f 03* teletypi 
writers — Gleichlauf . * A TXCOM publication. 

^'Detailed Feuersteln Technical Project Report 
No. 7s Investigation of SZ Cipher Machines a 
Feuerstein Laboratory." A TICOM publication. 

Sees Gearing * s "Research" Bureau. 
I or enz Aktiengesellachaf t, Berlin* Muelhausen 
Thuer. Firm which worked on speech encipher 
and developed teleprinter enciphering devic 

, Member of Wanderer Co. 



p * m * 



Feuersteln Laboratory .... Electronic research laboratory 

owned and managed by a Dr. Oskar Vierling. This is 
described in Volume 8 of this paper. 

Fricke, Or. Walter, Technician/ grade of Lieutenant. Head of 

Section lib ot the Signal Intelligence Agency of the 
Supreme Command Armed Forces (QKW/Chl). Specialized 
v in the production of codes and ciphers. 

Foreign Office, Cryptknalytic Section (Pers Z S) and Foreign 

Office Cryptographic Section (Pers Z Chi),. These 
made up one of the six principal German cryptologic 
organizations. These are described in^Volumes 1 

and 6 of this paper. 
Frowein, Lt. R. Hans -Joachim. Assigned temporarily to the 

Signal Security Agency of the Bavy High Command 
(OKM/4 SKL/II) in l<m to make security studies 
on the Enigma, He had no previous experience with 
this machine and yet developed a workable solution. 
Weather Bureau (Reichswetterdienst) . This service was 
charged with cryptanalysis of enemy meteorological 
ciphers. It was part of the German Air Force, and 

sintained close liaison with the Signal Intelligenc 
Agency of the Commander in Chief of the Air Force 
(Chl-S telle ^ Ob d L) . 
Goering's Research Bureau (Reichsluf tfahrtministerium Fors- 

chungsamt, abbreviated FA). This was one of the six 
principal German cryptologic organizations, and is 
described In Volumes 1 and 7 of this paper. 



88 



V 



DOCID: 3560816 




1-1. 
1-6. 



1-20 




Helms oeth & Rinke. German firm engaged In manufacture of 

Enigma rotors and parts. 
Herzfeld, Corporal He int a Wolfgang. Member of Gruppe IV, 

Signal Intelligence Agency of Army High Command 
(OKH/GdKA) j formerly member of British, Italian, 
and Balkan sections of Inspectorate 7/vl (In 7/TL) . 
Huettenhain, Specialist Dr. Erich.. Principal crypt analyst of 
x the Signal Intelligence Agency of the Supreme Command 

Armed Forces (OKW/Chi) from 1939 to end of war. 
"Report of TICOM Reporting Team No. 3. A TICOM 
publication 

"Interrogation of Lt. D.R. Muentz of the 0104 4/m • " 
A TICOM publication. 

"Interrogation of Sonderfuehrer Dr. Fricke of the 
Signal Intelligence Agaacy of the Supreme Command 
Armed Forces ( OKW/Chi) A TICOM publication. 
1-31. "Detailed Interrogations of Dr. Hue ttenMin, Formerly 

Head. of Research Section of OKW/Chi, l8th-21st June 
1945." A TICOM publication. 
1-37. "Translation of Paper Written by Reg. Rat. Dr. Huet- 
tenhain of OKW/Chi on Special Apparatus Used as Aids 
to Cryptanalysis . " A TICOM publication, 
"Report on Interrogation of Lt. Frowein of OKM/4 SKL/lII, 
on His Work on the Security of the German Haval Four- 
wheel Enigma." A TICOM publication. 
"OKW/Chi Cryptanalytie Research on Enigma, Hagelin, 
and Cipher Teleprinter Machines." A TICOM publication. 
"P/W Situation Report." A TICOM publication. 
1-50. "Paper Written by Lt. Muentz of GKM/4 SKL/lII on 

Statistical Solution of the M-209 Hagelin Machine." 



1-38 



1-45, 
I -4? . 



1-51. 



I -52 . 
1-53 . 
1-57. 

1-58. 



A TICOM publication. 

"Interrogation Report on Uffz. Herzfeld, Heintz 
Worfgang, and Translation of a Paper He Wrote on the 
British War Office Code." A TICOM publication. 
"Papers Written by Uffz. Herzfeld on Mihailovlo and 
Tito Ciphers." A TICOM publication. 
"Construction of Schluesselgeraet 39." A TICOM 

publication. 

"Enciphering Devices Worked on by Dr. Liebknecht at 
Wa Pruef 7. A TICOM publication. 
"Interrogation of Dr. Otto Buggisch of OKW/Chi." 

A TICOM publication. 



\ 



\ 



89 




\ 



D 



3560816 



\ 



1-64. 
I -66 . 
I -67 . 
1-69. 



1-72. 
1-73. 
1-77. 



1-78. 



1-80. 
1-84. 

h 

r ■ 

1-88. 



1-89 * 

1-92. 

1-93. 
I -96 . 



1-103. 



1-104. 



1-112. 



I -113 . 



Buggisch on S.O. 



Buggisch. " 



\ 



"Answers by Wm.- Buggisch of OKH/Chl to Questions 
sent by TIOOM." A TICOM publication. 
"Paper by Dr. Otto Buggisch of OKH/ln 7Al and OKW/Ghi 
on Typex." A TICOM publication. 

"Paper by Dr. Otto Buggisch of OKH/ln 7/Vl and OKW/Chi 
on Gryptanaly tic Machines . " A TICOM publication. 

"Summary of Cipher Information on Jugoslav Traffic 
Provided byUffz. Herzfeld (Appendices to TICOM/ 
1-52) " A TICOM publication. 

"First Part of- the Report by W; 

41." A TICOM publication. 
"Translated Version of Homework done by Wi 
A TICOM publication. 

"Translations of Joint Report made by Drs. Huettsnhain 

and Fricke on the "£ aehlwerk " Enigma Machine." 
A TICOM publication. / 
"Interrogation of Oberstlt. Mettig on the History 
and Achievements of OKE/AHA/I n 7Al . " A TICOM 
publication. 

"P.O.W. Interrogation Report =-0bgefr. Clement Scr.usk 
Insp. VII/6 (OKH) A TICOM publication. 
"Further Interrogation of R.R. Dr. Huettenhain and 

Sdf . Dr. Fricke of OKW/Chi." A TICOM publication, 
"Report on Interrogation of ME. X. Vetterlein of the 

Reichspost Laboratorium on German Interception of 
Transatlantic Speech Circuits." A TICOM publication. 
"Report by Prof .Dr. H. Rohrbaeh of Pers Z S on Amer- 
ican Strip Cipher." A TICOM publication. ' 
"Final Interrogation of the Wachtmeister Otto Buggisch 

(OKH/ln 7/VI and OKW/Chi)" A TICOM publication. 
"Detailed Interrogation of Members of OKM/4 SKL/lII 

At Flensburg," A TICOM publication. 
"Interrogation of Oberstlt. Mettig on the Organi- 
sation and Activities of OKW/Chi." A TICOM publi- 
cation. V 

r 

"Second Interrogation of Reg. Rat Hermann Scherschmidt 
of Pers 2 S Ausuaertiges Amt. on Turkish and Bul- 
garian Systems." A TICOM publication. 
"Report on Berlin Targets by Major Heller of G.S.I.(S) 

21 A.G., B.A.O.R." A TICOM publication. 

"Preliminary Interrogation of Reg. Rat. Dr. Ferdinand 
Voegele (Chi Stelle, Ob d. L) and Major Ferdinand 
Feichtner (O.C. of Regt. 352, Etc.)" A TICOM 

publication. ' 
"Interrogation of Major Dr. Rudolph Hentze, Head of v 
Gruppe IV (Cryptanalysis), General der Kachrichten- 

auf klaerung . " A TICOM publication. 



90 



DOCID: 3560816 





I -118 



I *119 



1-127. 

1 

I -137 . 
1-146. 

1-147. 
1-149. 

1-152 . 
I -I69. 
1-173. 

1 

IF -107. 



IP -123. 



IF-142. 



"Joint Reports by Reg: Rat. 

Dr. Pricks., Written at C.S.D.I.C. 



Rat. 
SIgint . " 



Voegele and 
A TICOM publi- 



Mettig of OKW/Cnl 



If 



Dr. Huettenhain and Sdf 

1 

on or about 28th 
August 19^5." A TICOM publication, 
"Further Interrogation of Reg. 
Major Feichtn©^ on G.A.F. 

cation. 

"Interrogation of Oberstlt 
A TICOM publication, 

"Final Report Written by Wachtmeister Otto Buggisch 

of OKH/Chi and QKW/ChiA A TICOM publication. 
"Detailed Interrogation^ of Members of OKM/4 SKL/III 
At Flensburg." A TICOM publication. 
"Detailed Interrogation of Members of OKM/4 SKL/III 

At Flensburg." A TICOM publication. 

"Report by Uffz. Karrenberg and Colleagues oil Allied 

Cypher Machines." A TICOM publication. 

"Second Homework and Report on Further Interrogation 

of RR Voegele." A TICOM publication. 

"Report by Xlffz. Karrenberg on the Bandwurm." A 

TICOM publication. , 

"Report by the Karrenberg Party on Russian W/T," 

A TICOM publication,, 

"Extracts from Report on Interrogation of Dr. Hans 
Wilhelm Thost." A TICOM publication. 
"Interrogation of P. 0 0 W. Werner Graupe by interroga- 
tors of Signal Intelligence Division/ ETOUSA. 
"Consolidated Report on Information Obtained fro 
Following; Erdmann, Grubier, Hempel, Karrenberg, 
Schmits, and Suschowk." A publication of the Com- 
bined Services Detailed Interrogation Centre, num- 
ber CSPIC> (UK) SIR 1717. 

"Naval Cipher and W/T, Procedures. MarineschSussse 
dienst und Marinefunkverfahren. " A British Naval 



the 



Intelligence Division publication, number TR/PG/ 
17626/fJID. 

IF-17f>. ^eabourne report, Volume XIII. "Cry£tanalysis 

Within the Luftwaffe SIS." , 24 November 1.9^5 c 
"Radar Most Decisive Waapon, Won Ocean Fight Says 
Doenitz." United Press Article in the Washington 
JP_ost 10 May 19^6. 
tin YAl- See Inspectorate 7/VT. - ' 

Inspectorate 7/VI ,(0KH/ln 7Al)"» Central Cryptanalytic 

Agency of She Army High Command for Non-Ru&sian 



F-259- 




Traffic 1942-1945. 



Member of Section IVb of the 

and 



Mill 



Jensen, Graduate Engineer. 

Signal Intelligence Agency of the Supreme Co 

Armed Forces (OKW/Chi) which dealt 'with the deve 
lopment of cryptanalytic machinery. 




91 



ID: 3560816 



\ 



Karrenber Corporal Erich, Cryptanalyst of Signal Intel! I - 

g mce Agency of Army High C ommand ( OKH/GdNA ) who 
studied Baudot traffic „ 



Xonski and Krueger, Barlih 

; fen? the Enigma, 



Firm which manufactured rotors 



Krachel 



c. • « # 



Working engineer who came to Signal Intelli- 



gence Agency of the Supreme Command of the Armed 
Forces [OKW/Chi) In 1941 to help Rotscheidt and 



Jensen in research on cipher 
Kunze, Dr. Werner. 



tachines . 



Head of mathematical cryptographic sub- 
section of Pers Z S. ■ * 

Liebknecht, Graduate Engineer Dr. Werner. Chief of section 



M-ll. 

Martini 



Illh of Army Ordnance. Development and Testing 
Group, Signal Branch (wa Fruef 7) * Maintained 
technical liaison with Dr. Huettenhain of the 



Signal Intelligence Agenc^ of the Supreme Command 
Armed Forces (OKW/Chi 

Five drawings of the Lueckenfuellerwalze. 
Lt. General Hermann. Chief Signal Officer, German 

Air Force o 



Menzer, Senior Inspector, Chief of Section lie of Signal 

Intelligence Agency of the Supreme Command of the 
Armed Forces (OKW/Chi) which dealt with the devel- 
opment and production of special ciphers for. govern- 

ent departments* industry, and the Main Reich 
Security Office (RSHA), developing of deciphering 
aids for agents . 
Mettig, Lt. Col. Head of Inspectorate 7/0 (m 7/Vl) from 

Nov. 19*1 to June 19*3 i second in command of Signal 
Intelligence Agency of the Supreme Command Armed 

Forces iOKW/Chi) from Dec. 19*3 to April 19*5. 
Military Intelligence (Abwehr). Military intelligence and 

counter espionage section of the Supreme Command of 
the Armed Forces (OKW). After 20 July 19** , this 

section was taken over by RSHA. , ^ 
Muentz, Lt. ..... Member of the Signal IntelHgence,4gency of 

the Navy High Command (OKM/4 SKL/III) who wbrked 
on the Havy Hagelin Machine —M- 209. j 
OKH/GdNA * See Signal Intelligence Agency of the Army High 

Command. 

OKL/LN Abt 550. See Signal Intelligence Agency of the Air 

Force High Command. - ; 

OKW/Chi. See Signal Intelligence Agency of the Supreme 

Command Armed Forces. 

OKM/* SKL/lI '* See Signal Security Agenc& of the Havy High 

C ommand • 

0KM-* SKL/III See Signal Intelligence Agency of the Navy 

High Command. v 



92 



/ 



3560816 

p i 

a % 

i 

I 

* i » 

■ t 

i 



Pers Z CM, See Foreign Office Cryptographic Section, 
Pers Z 3. See Foreign Office Cryptanalytic Section. 

Pietsch, Specialist Dr. Head of mathematical section 

of Inspectorate 7 /VI (In 7Al) 

Rohrbach, Dr. Hans, Group head in Mathematical, and crypt- 
analytic subsection (Kunze) of Foreign Office 
Cryptanalytic Section (Pers Z S)„ Also Math Pro- 
fessor at University of Prague, 

Rotscheidt, Graduate Engineer, Appointed in 1941 to Signal 

Intelligence Agency of the Supreme Command Armed 
Forces 10KW/Chi) for Research in offensive and 
defensive warfare in cipher machines. Telecommuni- 
cation expert. 

Reich Security Office; Reichssicherheitshaupfcamtp abbre- 
viated RSHA, 

Reichsluf tfahrtministerium Forschungsamt. See Goe^ing f s 

^Research* Bureau. 

Relchsvetterdienst. See German Weather Bureau, 

Schaeffer Engineer who came to Signal Intelligence 

Agency of the Supreme Command Armed Forces (OKW/ 
Chi) in 194! to help Rotscheidt and Jensen in re- 
search on cipher machines. 

Schmaljs, Graduate Engineer. Head of Hollerith section of 

Signal Intelligence Agency of the, Navy High Command 
( OKM/4 SKL/III ) . 

Schuessler. iSngineer of I.B.M, Firm in charge of section 

workshop at Erfurt (section 4 of Gruppe IV 9 GdM) 
Schuck* Corporal Clemens. Cryptanalyst of Inspectorate 

who worked ori SLIDEX and M-209- 
Schultze, Amtsrat, Cryptographer of OKM/4 SKL/III. An expert 

on the Hagelln machine. 
Security Group of the Signal Intelligence Service (OKH/Gen 

Mafue/III, Gruppe IV). This service did security 

studies on German Air Force traffic. 

Siemens & Halske, Berlin, German commercial firm which 

worked on speech encipherment . 
Signal Intelligence Agency of the Air Force High Command 

(GKL/LK Abt 350), This was one of the six prin- 
cipal German cryptologic organizations. This 

agency is described in Voluine 5 of this paper. 
Signal Intelligence Agency of the Army High Command (OKH/ 

GdNA) . This was one of the six principal German 
cryptologic organizations. It is described .in 
' Volume 4 of this paper. 



93 



DOCID: 3560816 




Signal Intelligence Agency of the Supreme Command Armed Forces 

(OKW/Chi) „ This made up one of the six principal 

German cryptclogifc organizations* It is described 
in Volume 3 of this paper. 
Signal Security Agency of the Mavy High Command (OKM/4 SKL/lI) 

and Signal Intelligence Agency of the Uavy High Com- 
mand .(OKM/4 SKL/lII). These made up one of the six 
principal German cryptologic organisations. 
Sueddeutsche Apparate Fabrikeh* Berlin. German Commercial 

fir] 




tfhich worked on speech enc ipherment . 



OKW/Chi 



Stein, Lit. Dr* Head of the section of Gruppe IV of 

which concerned itself with security investigations 

for new procedures and all investigations on inven- 
tions . ^ ' 



T-372 . 



T -1282 . 



"The Enigma toy Dr. Rudolf Kochendoerffer, from 
Scientific Writings of Foreign Office f Cryptanalytic 
Section 8 Dec, 1$W1 A captured German document 
in possession of TICOM. 

A set of miscellaneous Foreign Office papers* in 




\ 



iscellanebus Foreign Office papers, 
possession of TICOM. 
Telefonbau U. Uormalzeit Co., Frankfurt am Main, Firm which 

built test models of Cipher Device 39 * ' 
Telefunken, Berlin. German commercial firm which worked on . 

speech encipherment . 

Todt, . Engineer who came to OKW/Chi in 1941 -to help 

Rotscheidt and .Jensen in research on cipher machines 

TranoWj Specialist ..... Head of English Cryptographic sec- 
tion in OK54-4 SKL/III. 

Vetterlein, Mr. K. Supervised the monitoring service in 

Holland for trans -Atlantic monitoring of telephone 

conversations, 

Vierling, Dr. Oskar. Specialized in communications equipment 

reaearch. Was owner and chief engineer of; the 

Feuer stein Laboratory. 
Voegele, Specialist Dr. Ferdinand. Chief of Section E of the 

Signal Intelligence Agency of the Commander in Chief 
of She Air Force (Chi-S telle Ob d L) and principal 
cryptanalyst in the German Air Force. 
Wa Pruef 7. See Army Ordnance, Development and Testing Group, 

Signal Branch. 

Wanderer Co. This firm was to have manufactured Cipher De- 
vice 39 on large scale production. 
Wetterdienst der Luftwaffe. See Air Force Weather *>ervice. 



9* 




V 



/. 



■- % 1 



. V 




••>.■ 





3 










'* Y 



4 










e Reflector Plate, 

the Enig»*. It la 

at left is rear 



_ Phot pgr apJi of German PI 

( Umkehrvalze D), 

described in Chapter II 

I view of plate shoving plugs Inserted In jacks; 
item In center la the metal cover; item at right 
■la face vlav of the complete assembly. This is 
| at preaent in Army Security Agenc 



Mus e am 







4 




3 






+£. JV. -V. I 





Ml 





3E 

^33 





BBS: 




unininin 




II*. Ite»»t. 



ft- *?:■■«■ 




Item In center 1» 

lt*» at right i» 



in A.r 





: 3560816 





- 



COMPARISON OF RAPID ANALYTIC MACHINERY - OKW/CHl AND A, 5. A. 



ID 



35608J6 



OKW/CHl) RAPID ANALYTIC MACHINERY 



AMERICAN (A.S.A.) RAPID ANALYTIC MACHINERY 



NAME 



PURPOSE 



,Dt GRAPHIC WEIGHT 
' RECORDER 

i 

( "BIGRAM^IuCHGE ' 



t 



/ 



POLYGRAPH) C COINCI - 
• -DENCE COUNTER - 

("SAEGEBOCK") 



SLIDING WHOLE MESSAGE AGAINST 
ITSELF; LISTING THE WEIGHTS 
OF THE RESULTANT DIGRAPHS. 
(ESPECIALLY DESIGNED TO SOLVE 
JAPANESE TRANSPOSITION M JAE.*0 

SLIDING MESSAGE AGAINST ANO- 
THER TO RECORD LOCATIONS OF 
COINCIDENCES. 



SEPARATE COUNTING OF MONO- 
^. GRAPHS, JR I GRAPHS, ETC . , UP 
TO DECAGRAPHS, COINCIDENT' BE 
TWEEN MESSAGES, OR REPEATING 
WITHIN A MESSAGE; AND A RE- 
CORDING OF THE SEPARATE TO- 
TALS THEREOF. 



MAKEREADY 
REGUl RED 



PUNCHING TELETYPE- 
WRITER TAPES. 
(D I GRAPHIC WEIGHTS 
ALREADY PLUGGED ON 
PLUGBOARD.) ' 



PUNCHING TELETYPE 
WRITER TAPES. 



statistical depth 
incpeaser- 

( "turmuhr") 



SIMPLE COUNTING 
APPARATUS 



DIFFERENCING CALCU- 
LATOR, NON RECORD 
)NG 



RAPID TESTING OF MESSAGES TO 
SEE IF ANY OF THEIR PARTS BE- 
LONG TO A GIVEN DEPTH OF 
STRIP-SYSTEM GENERATRICES. 
(ESPECIALLY DESIGNED TO SOLVE 
AMERICAN STRIP SYSTEM.) 



COUNTING OCCURRENCES OF FIG- 
URE DIGRAPHS Wl.THIN A MESS- 
AGE OP SET OF. MESSAGES. 
(10X10 CLASSES OF DIGRAPHS.) 



COMPUTING UNENC I PHERED CODE 
GROUPS RESULTING FROM APPLY 
ING TRIAL ADDITIVES TO A 
DEPTH OF ENCIPHERED CODE 
GROUPS I DIFFERENCING A 
DEPTH OF ENCIPHERED CODE 
GROUPS. DEPTH LIMITED TO 
30 GROUPS. 



DIFFERENCING CALCU- 
LATOR, RECORDING 



FLAGGING DIFFERENCES IN A 
DEPTH OF ENCIPHERED CODE 
GROUPS. NO LIMIT TO DEPTH. 



PUNCHING TELETYPE- 
WRITER TAPE. 
(SINGLE LETTER 
WEIGHTS ALREADY 
PLUGGED ON PLUG- 
BOARD. ) 



SPEED 



75 LETTERS 
PER SECOND 
USING TAPES 
OF ANY 
LENGTH. 




DATE 
ACCUIRED 



1 



LETTERS 
ER SECOND 
USING TAPES 
OF ANY 
LENGTH. 



NAME 



ELECTROMECHANAGRAM- 
MER 

(ATTACHMENT TO I .B.M. 
TABULATOR. ) 



HAWKINS 1 RES I STOP 
BOARD AND COUNTER. 



1 LETTER 1 
PER SECOND 
USING TAPE 
OF ANY 
LENGTH. 



PUNCHING TELETYPE- 
WRITER TAPE. 
(NECESSARY TO 

COPY OFF OR PHOTO- 
~GR APH" ANSWE RY J' - 



SETTING UP OF 
DEPTH MANUALLY. 
(PROBABLY 5 MINU- 
TES.) 



7 DIGRAPHS 
PER SECOND 
USING TAPE 
OF ANY 

uength; * - 



RAPID MANU- 
AL. 



PUNCHING TELETYPE- 
WRITER TAPES. 



LIKELY ADDITIVE 
SELECTOR 

J 

t 

("WITZKISTE") 



7 NUMBERS 
PER SECOND 
USING TAPE 
OF ANY 
LENGTH. 



19ll3? 



JOOS* TYPEWRITER 



INDEX OF COINCIDENCE 
MACHINE 



70 -MM, COMPARATOR 



PURPOSE 



SLIDING PART OF MESSAGE AGAINST 
WHOLE, LISTING TOTALS OF 
WEIGHTS OF RESULTANT DIGRAPHS. 
(ESPECIALLY DESIGNED TO SOLVE 
JAE.) 



MAKEREADY 

REQUIRED 



RECORDING TOTAL OF COINCIDENCES 
BETWEEN MESSAGES OR OF REPEATS 
WITHIN A MESSAGE. (NO SEPAR- 
ATE POLYGRAPH IC COUNT. T ' " " 



PULL ING I .B.M. 
CARDS BY HAND; 
WIRING PLUGBOARD 
FOR EACH TEST. 
(D I GRAPHIC 
WEIGHTS ALREADY 
PUNCHED IN CARDS) 



PUNCHING TELETYPE 
WRITER TAPE5. 



SFEED 



2 POSI- 
TIONS 

TESTED PER 
SECOND, US- 
ING CARD 
DECK OF ANY 
LENGTH. 



RECORDING TOTAL OF COINCIDENCES 
BETWEEN MESSAGES OR OF REPEATS 
WITHIN A MESSAGE. (NO SEPAR- 
ATE POLYGRAPH I C COUNT. ) 



INDICATING (BUT NOT EVALUATING 
OR RECORDING) TOTAL OF COINCI- 
DENCES BETWEEN MESSAGES, OR OF 
REPEATS WITHIN A MESSAGE . 
{ACTUAL COUNT MUST BE DONE BY 
EYE AFTER HIGH VALUED POINTS 
ARE FOUND. ) 



RECORDING SEPARATE TOTALS FOR 
ANY 5 PATTERNS UP TO TEN LET- 
TERS IN LENGTH, COINCIDING 
BETWEEN MESSAGES OR REPEATING 
WITHIN A MES5AGE. ( A "PAT- 
TERN" MAY BE, FOR EXAMPLE, A 
D I GRAPH -SPACE- TR I GRAPH . ) 



PUNCHING TELETYPE 
WRITER TAPES. 



PUNCHING TELETYPE- 
WRITER TAPES; 
PHOTOGRAPHING AND 
DEVELOPING PLATES 



PUNCHING 70-MM, 
TAPES. 



7 LETTERS 
TESTED PER 
SECOND, US- 

,.LNG TAPE..- . 
OF ANY 
LENGTH. 



7 LETTERS 
TESTED PER 
SECOND, US- 
ING TAPE 
OF ANY 
LENGTH. 



INSTANTANE- 
OUS OVER 
SPAN OF 
600 LETTERS 
ONLY. 



DAtE 

ACGUI RED 

1 



i9li0 
(NOW ob- 
solete) 



19^3 



19*13 



300 LETTERS 

EXAMINED 
PER SECOND 
USING TAPES 
OF ANY 
LENGTH. 



19M 



f -w 



(NONE COMPARABLE; WOULD PROBABLY ADAPT REGULAR I .B.M. PROCEDURES.) 



19ii3? 



191J3? 



D I GRAPHIC FREQUENCY 
COUNTER OP "FREAK" 
(BEING BUILT.) 



19113? 



ti 



NATIONAL CASH REGIS 
TER DIFFERENCING 
CALCULATOR 



COUNTING OCCURRENCES OF LETTER 
OP FIGURE DIGRAPHS WITHIN A 
MESSAGE OP SET OF MESSAGES. 



T — 




1 T 



COMPUTING UNENC I PHERED CODE 
GROUPS RESULTING FROM APPLY- 
ING TRIAL ADDITIVES TO A 

DEPTH OF ENCIPHERED CODE 
GROUPS: DIFFERENCING A DEPTH 
OF ENCIPHERED CODE GROUPS. 
DEPTH LIMITED TO 20 GROUPS. 



PUNCHING TAPES. 



V -3-™ 



(ESTIMATED: ) 
7 DIGRAPHS ! 
PER SECOND) 



DUE IN 

19^6 



7 «c 



SETTING UP OF 
DEPTHS ELECTRIC- 
ALLY. (ABOUT 

1 MINUTE.) 



xz 



RAPID MANU- 
AL. 



19^ 



X 



(NONE COMPARABLE; WOULD USE REGULAR I .B.M. PROCEDURES, PROBABLY WITH PRE-SENSING GANG PUNCH.) 



RECORDING SCORES SHOWING STA- 
TISTICAL LIKELIHOOD OF EACH 
POSSIBLE ADDITIVE, IF APPLIED 
TO A GIVEN DEPTH OF ENCIPHERED 
CODE GROUPS. PRACTICAL LIM- 
ITS OF DEPTH, 5 TO 20. 
(ADAPTABLE TO NON -NORMAL 
ARITHMETIC IF SUFFICIENTLY 
LARGE DECK OF SPECIAL PLATES 
HAS. BEEN PREPARED. ) 



J. 



(NO MAKEREADY AS 
USED PREMADE 
PHOTOGRAPHIC 
PLATE. ) 

(PHOTOGRAPHING 
OF ANSWER RE- 
GUIpED. ) 



ABOUT 1 TO 
MINUTES 
'ER AVER- 
AGE DEPTH. 




lol|3? 



LIKELY ADDITIVE SE- 
LECTOR. (PROPOSED 
AND TESTED BUT 
NEVER USED.) 



KEY FINDER. 
(ATTACHMENT TO 
I. B.M. TABULATOR.) 



(NONE COMPARABLE; GERMAN NAVY ADAPTED REGULAR I .B.M. PROCEDURES TO ACCOMPLISH (J- 1 1*6 ) . > 



(NONE COMPARABLE; PROBLEM DID NOT ARISE.) 



SLIDE RUN MACHINE 
(ATTACHMENT TO 
I .B.M. MACHINE. ) 



"CAMEL" 

(ATTACHMENT TO 
I. B.M. MACHINE) 



RECORDING TALLIES SHOWING STA- 
TISTICAL LIKELIHOOD OF EACH 
POSSIBLE ADDITIVE, IF APPLIED 
TO A GIVEN DEPTH OF ENCI- 
PHERED CODE GROUPS. PRACTI- 
CAL LIMITS OF DEPTH, 5 TO 20. 
(ADAPTABLE TO NON-NORMAL 
ARITHMETIC IF SUFFICIENTLY 
LARGE DECK OF SPECIAL CARDS 
OR PHOTOGRAPHIC PLATES HAS 
BEEN PREPARED. ) 



(NO MAKEREADY AS 
* USED PREMADE 
PUNCHED CARDS 
OR PHOTOGRAPHIC 
PLATE.) 
(PHOTOGRAPHING 
OF ANSWER RE- 
QUIRED.) 



ABOUT 1 TO 
MINUTES 
'ER AVER- 
AGE DEPTH 



TESTED 
IN 
19I13 



RECORDING MOST LIKELY ADDI- 
TIVES AND RESULTANT UNENC I - 
PHERED CODE GROUPS, WHEN 
TESTING DEPTHS OF UP TO 20 
ENCIPHERED COOE GROUPS. 
(ADAPTABLE EGUALLY WELL TO 
NORMAL OR NON-NORMAL ARITH- 
METIC.) 



DETERMINING AN ENCIPHERED CODE 
MESSAGE'S ENC I PHERMENT -START - 
ING-POINT IN A BOOK OF KNOWN 
ADDITIVES. THIS IS DONE BY 
TESTING 8 CONSECUTIVE ENCI- 
PHERED COOE GROUPS AGAINST A 
DECK OF ADDITIVE "CARDS", AND 
SCORING TRIAL DECIPHERMENTS. 
(ADAPTABLE EGUALLY WELL TO 
NORMAL OR NON-NORMAL ARITH- 
METIC.) 



PUNCHING OF I .B.M. 
CARDS FOR GROUPS 
IN DEPTH. (PLUG- 
BOARDS ALREADY 
WIRED FOR SCORES 
INVOLVED. ) 



3 MINUTES 
PER DEPTH 

or 20. 



191*3? 



PUNCHING OF CIPHER 
CARDS. (PLUG- 
BOARD ALREADY 
WIRED; CARD DECK 
OF ADDITIVES AL- 
READY PUNCHED.) 



25 COMPLETE 
TESTS PER 
SECOND . 



19^3 



( NONE. •EXACJL.Y-C0MRARABLE.; ! .-AC;T 1 UALLY— USED. REGULAR l-.B.M. .PROCEDURES -OR COULD ADOPT 
"POLYGRAPHIC COINCIDENCE COUNTER", "D I GRAPHIC WEIGHT RECORDER"; OR PROPOSED "' 
"REPEAT FINDER. ") 



v - 



BRUTE FORCE 
»-(.AXTACHME.N.T__TO. 
lVB^MV~MACHTNE )" 



REPEAT FINDER 
(WAS BEING BUILT) 



SEARCHING MASS OF MESSAGES FOR 
REPEATS OF 5 LETTERS OR MORE 
BETWEEN THEM. 



; 



PUNCHING TELETYPE- 
WRITER TAPES; 
PHOTOGRAPHING AND 
DEVELOPING FILMS. 



10,000 PER 
SECOND US- 
ING ANY 
LENGTH Fl LM. 



i 



WAS 
STILL 
TO BE 
DELI V 
ERED. 



(NONE COMPARABLE.) 



i 

\ TETRA-TESTER 



PERMITS DISCOVERY OF MESSAGES 
(IN CERTAIN JAPANESE ARMY 
CODE SYSTEMS) LIKELY TO CON- 
TAIN CERTAIN SPECIFIED CLASSES 
OF PLAIN TEXT. 



PUNCHING I. B.M. 
CARDS FOR MESS- 
AGES. 



3 OR k MESS- 
AGES TESTED 
PER MINUTE 



19145 



INDEXING IN-PHASE BUT NOT NEC- 

FSSAR.I.LY C.CNSECUTJ,VE. ^REPEATS,, 
'-BETWEEN MESSAGES.- (REPEATS "NO 
MORE THAN !8 GROUPS APART.) 



5202 



DRAGON 



FINDING REPEATS OF ANY GIVEN 
TYPE PATTERN, BETWEEN MESSAGES. 



ESPECIALLY ADAPTEO TO BREAKING 
5 PERIODIC WHEELS OF GERMAN 
TELETYPE ENCIPHERING DEVICES, 
FROM A GIVEN MESSAGE. 



ESPECIALLY ADAPTED TO SETTING 
A CRIB AGAINST PARTIALLY 
SOLVED GERMAN TELETYPE ENCI- 
PHERED MESSAGE, SO AS TO AID 
FINAL SOLUTION. 



PUNCHING I. 8-M. 
.CARES ^FOR „£1£SS - 
" AGES AND- EXPAND 

ING DECK TO ONE 
CARD PER CIPHER 
GROUP. 



PUNCHING TELETYPE- 
WRITER TAPES; 
PHOTOGRAPHING AND 
DEVELOPING FILMS. 

(PHOTOGRAPHING OF 
ANSWERS REGUl RED.) 



PUNCHING TELETYPE- 
WRITER TAPES; 
PHOTOGRAPHING AND 
DEVELOPING FILMS. 



5,000 POSI 
TIONS PER 
SECOND US 
ING FILM 
OF ANY 
LENGTH. 



19l|l4 



PUNCHING TELETYPE 
WRITER TAPES. 



5,000 POSI 
TIONS PER 
SECOND US 
ING FILM 
OF ANY 

' LENGTH. ' 



- ( 



19I45 



) 



5 MINUTES 
PER MESS- 
AGE PER 
CRIB, US- 
ING TAPE 
OF ANY 

LENGTH. 



I9I45 



(NONE COMPARABLE. ) 



"003* OR "MADAME X" 
CBOMBE") 



SINGLE FRAME 

DUO-BUSTER 

ATTACHMENT 



SCRITCHER 



ESPECIALLY DESIGNED TO SOLVE 
END PLATE STECKER, WHEEL 
ORDER AND WHEEL SETTINGS, OF 
A GERMAN ARMY ENIGMA, FROM A 

GIVEN CIPHER MESSAGE AND 
CRIB. 

ESPECIALLY DESIGNED TO SOLVE 
WHEEL SETTINGS WHEN STECKER 
AND WHEEL ORDER ARE KNOWN. 



I 



ESPECIALLY DESIGNED TO SOLVE 
END PLATE STECKER, WHEEL 
ORDER, WHEEL SETTINGS, AND 
REVERSING WHEEL WIRING, OF 
A GERMAN ARMY ENIGMA, FROM 
A GIVEN CIPHER MESSAGE AND 
CRIB. 



PLUGGING UP PLUG- 
BOARD. 



T 



PLUGGING UP PLUG- 
BOARD. 



1»0 PER 
SECOND 



19^3 



25 PER 

Second 
("super" 

STILL TO 
COME WILL 
HAVE SPEEO 
OF 1,000 
TO 10,000 
PER SECOND.) 



191*5 



